{"grype_matches":[{"artifact":{"id":"9361a461f1bc8b3d","cpes":["cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.47-r0:*:*:*:*:*:*:*"],"name":"graphicsmagick","purl":"pkg:apk/alpine/graphicsmagick@1.3.47-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"1.3.47-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gm"},{"path":"/usr/lib"},{"path":"/usr/lib/libGraphicsMagick.la"},{"path":"/usr/lib/libGraphicsMagick.so.3"},{"path":"/usr/lib/libGraphicsMagick.so.3.27.0"},{"path":"/usr/lib/libGraphicsMagickWand.la"},{"path":"/usr/lib/libGraphicsMagickWand.so.2"},{"path":"/usr/lib/libGraphicsMagickWand.so.2.11.0"},{"path":"/usr/lib/GraphicsMagick-1.3.47"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/delegates.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type-ghostscript.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type-solaris.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type-urw-base35-otf.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type-windows.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/aai.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/aai.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/art.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/art.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/avs.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/avs.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/bmp.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/bmp.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/braille.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/braille.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cals.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cals.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/caption.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/caption.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cineon.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cineon.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cmyk.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cmyk.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cut.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cut.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dcm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dcm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dcraw.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dcraw.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dib.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dib.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dpx.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dpx.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ept.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ept.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/fax.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/fax.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/fits.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/fits.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gif.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gif.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gradient.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gradient.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gray.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gray.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/heif.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/heif.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/histogram.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/histogram.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/hrz.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/hrz.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/html.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/html.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/icon.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/icon.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/identity.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/identity.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/info.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/info.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/jnx.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/jnx.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/jpeg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/jpeg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/label.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/label.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/locale.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/locale.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/logo.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/logo.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mac.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mac.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/map.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/map.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mat.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mat.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/matte.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/matte.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/meta.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/meta.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/miff.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/miff.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mono.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mono.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpc.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpc.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpeg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpeg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpr.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpr.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/msl.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/msl.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mtv.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mtv.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mvg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mvg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/null.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/null.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/otb.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/otb.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/palm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/palm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcd.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcd.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcl.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcl.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcx.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcx.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pdb.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pdb.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pdf.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pdf.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pict.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pict.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pix.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pix.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/plasma.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/plasma.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/png.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/png.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pnm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pnm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/preview.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/preview.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps2.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps2.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps3.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps3.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pwp.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pwp.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rgb.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rgb.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rla.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rla.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rle.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rle.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sct.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sct.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sfw.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sfw.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sgi.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sgi.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/stegano.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/stegano.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sun.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sun.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/svg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/svg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tga.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tga.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tiff.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tiff.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tile.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tile.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tim.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tim.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/topol.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/topol.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ttf.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ttf.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/txt.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/txt.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/uil.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/uil.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/url.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/url.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/uyvy.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/uyvy.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/vicar.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/vicar.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/vid.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/vid.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/viff.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/viff.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wbmp.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wbmp.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/webp.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/webp.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wmf.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wmf.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wpg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wpg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xbm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xbm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xc.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xc.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xcf.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xcf.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xpm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xpm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/yuv.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/yuv.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/filters"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/filters/analyze.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/filters/analyze.so"},{"path":"/usr/share"},{"path":"/usr/share/GraphicsMagick-1.3.47"},{"path":"/usr/share/GraphicsMagick-1.3.47/config"},{"path":"/usr/share/GraphicsMagick-1.3.47/config/colors.mgk"},{"path":"/usr/share/GraphicsMagick-1.3.47/config/log.mgk"},{"path":"/usr/share/GraphicsMagick-1.3.47/config/modules.mgk"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"graphicsmagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2007-0770","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.47:*:*:*:*:*:*:*"],"package":{"name":"graphicsmagick","version":"1.3.47-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2007-0770","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-0770","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0770","date":"2026-10-08","epss":0.05403,"percentile":0.92479}],"risk":4.538520000000001,"urls":["http://secunia.com/advisories/24167","http://secunia.com/advisories/24196","http://www.debian.org/security/2007/dsa-1260","http://www.mandriva.com/security/advisories?name=MDKSA-2007:041","http://www.novell.com/linux/security/advisories/2007_3_sr.html","http://www.osvdb.org/31911","http://www.securityfocus.com/archive/1/459507/100/0/threaded","http://www.ubuntu.com/usn/usn-422-1","https://issues.rpath.com/browse/RPL-1034"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-0770","description":"Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456."},"relatedVulnerabilities":[]},{"artifact":{"id":"34a0a5e3ece0fdd0","cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:tiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:tiff:4.7.1-r0:*:*:*:*:*:*:*"],"name":"tiff","purl":"pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"4.7.1-r0","language":"","licenses":["libtiff"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libtiff.so.6"},{"path":"/usr/lib/libtiff.so.6.2.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"tiff"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-52356","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1:*:*:*:*:*:*:*"],"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-52356","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-52356","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-52356","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-52356","date":"2026-10-08","epss":0.02187,"percentile":0.81857}],"risk":1.64025,"urls":["https://access.redhat.com/errata/RHSA-2024:5079","https://access.redhat.com/errata/RHSA-2025:20801","https://access.redhat.com/errata/RHSA-2025:21994","https://access.redhat.com/errata/RHSA-2025:23078","https://access.redhat.com/errata/RHSA-2025:23079","https://access.redhat.com/errata/RHSA-2025:23080","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:5958","https://access.redhat.com/errata/RHSA-2026:7081","https://access.redhat.com/errata/RHSA-2026:7304","https://access.redhat.com/errata/RHSA-2026:7335","https://access.redhat.com/errata/RHSA-2026:8746","https://access.redhat.com/errata/RHSA-2026:8747","https://access.redhat.com/errata/RHSA-2026:8748","https://access.redhat.com/security/cve/CVE-2023-52356","https://bugzilla.redhat.com/show_bug.cgi?id=2251344","https://gitlab.com/libtiff/libtiff/-/issues/622","https://gitlab.com/libtiff/libtiff/-/merge_requests/546","http://seclists.org/fulldisclosure/2024/Jul/16","http://seclists.org/fulldisclosure/2024/Jul/17","http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://seclists.org/fulldisclosure/2024/Jul/21","http://seclists.org/fulldisclosure/2024/Jul/22","http://seclists.org/fulldisclosure/2024/Jul/23","https://lists.debian.org/debian-lts-announce/2024/03/msg00011.html","https://lists.debian.org/debian-lts-announce/2025/01/msg00019.html","https://support.apple.com/kb/HT214116","https://support.apple.com/kb/HT214117","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120","https://support.apple.com/kb/HT214122","https://support.apple.com/kb/HT214123","https://support.apple.com/kb/HT214124"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52356","description":"A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63076"},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63076"},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"risk":1.15275,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-18798"},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"risk":1.15275,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-18798"},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"risk":1.08946,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63073"},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"risk":1.08946,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63073"},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"34a0a5e3ece0fdd0","cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:tiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:tiff:4.7.1-r0:*:*:*:*:*:*:*"],"name":"tiff","purl":"pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"4.7.1-r0","language":"","licenses":["libtiff"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libtiff.so.6"},{"path":"/usr/lib/libtiff.so.6.2.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"tiff"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6277","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1:*:*:*:*:*:*:*"],"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6277","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6277","date":"2026-10-08","epss":0.0181,"percentile":0.77958}],"risk":1.04075,"urls":["https://access.redhat.com/security/cve/CVE-2023-6277","https://bugzilla.redhat.com/show_bug.cgi?id=2251311","https://gitlab.com/libtiff/libtiff/-/issues/614","https://gitlab.com/libtiff/libtiff/-/merge_requests/545","http://seclists.org/fulldisclosure/2024/Jul/16","http://seclists.org/fulldisclosure/2024/Jul/17","http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://seclists.org/fulldisclosure/2024/Jul/21","http://seclists.org/fulldisclosure/2024/Jul/22","http://seclists.org/fulldisclosure/2024/Jul/23","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJIN6DTSL3VODZUGWEUXLEL5DR53EZMV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7ZGN2MZXJ6E57W3L4YBM3ZPAU3T7T5C/","https://security.netapp.com/advisory/ntap-20240119-0002/","https://support.apple.com/kb/HT214116","https://support.apple.com/kb/HT214117","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120","https://support.apple.com/kb/HT214122","https://support.apple.com/kb/HT214123","https://support.apple.com/kb/HT214124"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6277","description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB."},"relatedVulnerabilities":[]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"risk":0.76575,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14457"},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"risk":0.76575,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14457"},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-19931"},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63072"},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63072"},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80231","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-80231","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80231","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80231","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80231","date":"2026-10-08","epss":0.00898,"percentile":0.58384}],"risk":0.6735,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-80231"},"relatedVulnerabilities":[{"id":"CVE-2026-80231","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80231","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80231","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80231","date":"2026-10-08","epss":0.00898,"percentile":0.58384}],"urls":["https://curl.se/docs/CVE-2026-80231.html","https://curl.se/docs/CVE-2026-80231.json","https://hackerone.com/reports/3969368"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80231","description":"A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup\nfor a given hostname even when using a different Native CA Store setting\n(`CURLSSLOPT_NATIVE_CA`) than when the connection was created."}]},{"artifact":{"id":"bb3bb0d123bb84ee","cpes":["cpe:2.3:a:handlebars.js_project:handlebars.js:4.7.9:*:*:*:*:node.js:*:*","cpe:2.3:a:handlebarsjs:handlebars:4.7.9:*:*:*:*:node.js:*:*"],"name":"handlebars","purl":"pkg:npm/handlebars@4.7.9","type":"npm","version":"4.7.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/handlebars@4.7.9/node_modules/handlebars/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/handlebars@4.7.9/node_modules/handlebars/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.7.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8r5x-fm3f-whwj","versionConstraint":">=4.0.0,<=4.7.9 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"handlebars","version":"4.7.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-8r5x-fm3f-whwj","fix":{"state":"fixed","versions":["4.7.10"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"4.7.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106446","cwe":"CWE-94","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106446","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106446","date":"2026-10-08","epss":0.0064,"percentile":0.49078}],"risk":0.6016,"urls":["https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-8r5x-fm3f-whwj","https://nvd.nist.gov/vuln/detail/CVE-2026-106446","https://github.com/handlebars-lang/handlebars.js/pull/2185","https://github.com/handlebars-lang/handlebars.js/commit/703fdcc5fd6cc8d1cc0c33cc19de40c467c4b8d2","https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10"],"severity":"Critical","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8r5x-fm3f-whwj","description":"Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)"},"relatedVulnerabilities":[{"id":"CVE-2026-106446","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106446","cwe":"CWE-94","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106446","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106446","date":"2026-10-08","epss":0.0064,"percentile":0.49078}],"urls":["https://github.com/handlebars-lang/handlebars.js/commit/703fdcc5fd6cc8d1cc0c33cc19de40c467c4b8d2","https://github.com/handlebars-lang/handlebars.js/pull/2185","https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10","https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-8r5x-fm3f-whwj"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106446","description":"Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object instead of a template string can place JavaScript expressions in unchecked values such as Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original. The compiler emits those values into generated JavaScript, causing code execution in the server process when compile output renders or wherever precompile output is loaded. Applications that pass only template strings are not affected. This issue is fixed in version 4.7.10."}]},{"artifact":{"id":"419bb9cfaac3bb02","cpes":["cpe:2.3:a:libexpat:libexpat:2.8.3-r1:*:*:*:*:*:*:*"],"name":"libexpat","purl":"pkg:apk/alpine/libexpat@2.8.3-r1?arch=x86_64&distro=alpine-3.24&upstream=expat","type":"apk","version":"2.8.3-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libexpat.so.1"},{"path":"/usr/lib/libexpat.so.1.12.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"expat"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.8.4-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"< 2.8.4-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"expat","version":"2.8.3-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-66046","fix":{"state":"fixed","versions":["2.8.4-r0"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"2.8.4-r0"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"risk":0.60102,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-66046"},"relatedVulnerabilities":[{"id":"CVE-2026-66046","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"risk":0.5835,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63075"},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"risk":0.5835,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63075"},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"e62318d2e7910b78","cpes":["cpe:2.3:a:braces_project:braces:3.0.3:*:*:*:*:node.js:*:*","cpe:2.3:a:jonschlinkert:braces:3.0.3:*:*:*:*:node.js:*:*"],"name":"braces","purl":"pkg:npm/braces@3.0.3","type":"npm","version":"3.0.3","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/braces@3.0.3/node_modules/braces/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/braces@3.0.3/node_modules/braces/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vfj7-8cjw-p6xm","versionConstraint":"<=3.0.3 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"braces","version":"3.0.3"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-vfj7-8cjw-p6xm","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93687","cwe":"CWE-674","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93687","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"risk":0.5772,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-93687","https://github.com/micromatch/braces/issues/70","https://github.com/micromatch/braces/blob/3.0.3/lib/compile.js#L49-L53","https://github.com/micromatch/braces/blob/3.0.3/lib/expand.js#L102-L105","https://github.com/micromatch/braces/blob/3.0.3/lib/parse.js#L38-L40","https://www.vulncheck.com/advisories/braces-through-3.0.3-stack-overflow-via-deeply-nested-patterns"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vfj7-8cjw-p6xm","description":"braces vulnerable to stack-exhaustion denial of service through deeply nested patterns"},"relatedVulnerabilities":[{"id":"CVE-2026-93687","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93687","cwe":"CWE-674","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93687","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"urls":["https://github.com/micromatch/braces","https://github.com/micromatch/braces/blob/3.0.3/lib/compile.js#L49-L53","https://github.com/micromatch/braces/blob/3.0.3/lib/expand.js#L102-L105","https://github.com/micromatch/braces/blob/3.0.3/lib/parse.js#L38-L40","https://github.com/micromatch/braces/issues/70","https://www.vulncheck.com/advisories/braces-through-3.0.3-stack-overflow-via-deeply-nested-patterns"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93687","description":"braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14456"},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14456"},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"1d01ad883d38833b","cpes":["cpe:2.3:a:BinaryMuse:toml:3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:toml:toml:3.0.0:*:*:*:*:*:*:*"],"name":"toml","purl":"pkg:npm/toml@3.0.0","type":"npm","version":"3.0.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/toml@3.0.0/node_modules/toml/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/toml@3.0.0/node_modules/toml/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v5mp-jgw5-2x6j","versionConstraint":"<4.1.2 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"toml","version":"3.0.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-v5mp-jgw5-2x6j","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-09-04","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63376","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-63376","date":"2026-10-08","epss":0.00683,"percentile":0.51053}],"risk":0.5361549999999999,"urls":["https://github.com/BinaryMuse/toml-node/security/advisories/GHSA-v5mp-jgw5-2x6j","https://github.com/BinaryMuse/toml-node/commit/def6ab5ea99038c0dd482cd6af1745a6af8b4c44","https://github.com/BinaryMuse/toml-node/commit/dfaff662276adc38a2e03df3139f7119b0185463"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v5mp-jgw5-2x6j","description":"toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization"},"relatedVulnerabilities":[{"id":"CVE-2026-63376","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63376","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-63376","date":"2026-10-08","epss":0.00683,"percentile":0.51053}],"urls":["https://github.com/BinaryMuse/toml-node/commit/def6ab5ea99038c0dd482cd6af1745a6af8b4c44","https://github.com/BinaryMuse/toml-node/commit/dfaff662276adc38a2e03df3139f7119b0185463","https://github.com/BinaryMuse/toml-node/security/advisories/GHSA-v5mp-jgw5-2x6j"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63376","description":"toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-18924"},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"5e2ab97b23f852fa","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.2.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.2.0","type":"npm","version":"10.2.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.3.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mwp4-54f8-5fhr","versionConstraint":"<=10.3.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-mwp4-54f8-5fhr","fix":{"state":"fixed","versions":["10.3.1"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"10.3.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69192","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69192","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69192","date":"2026-10-08","epss":0.00663,"percentile":0.50143}],"risk":0.50388,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr","https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e","https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mwp4-54f8-5fhr","description":"ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-69192","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69192","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69192","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69192","date":"2026-10-08","epss":0.00663,"percentile":0.50143}],"urls":["https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e","https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69192","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1."}]},{"artifact":{"id":"d15158c33cd9e623","cpes":["cpe:2.3:a:\\@xmldom\\/xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*","cpe:2.3:a:xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*"],"name":"@xmldom/xmldom","purl":"pkg:npm/%40xmldom/xmldom@0.8.14","type":"npm","version":"0.8.14","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.8.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-27p8-2357-5qqv","versionConstraint":">=0.7.0,<=0.8.14 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@xmldom/xmldom","version":"0.8.14"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-27p8-2357-5qqv","fix":{"state":"fixed","versions":["0.8.15"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"0.8.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83608","cwe":"CWE-91","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83608","date":"2026-10-08","epss":0.00612,"percentile":0.47677}],"risk":0.49571999999999994,"urls":["https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv","https://nvd.nist.gov/vuln/detail/CVE-2026-83608","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/commit/57aec90ac57b4408ae7c5d1746bf2a693b5ed90e","https://github.com/xmldom/xmldom/commit/85f12eb4d14b44de33216cfb72b50af4d24e9fdd","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-27p8-2357-5qqv","description":"xmldom: DocType `name` Injection Bypasses requireWellFormed"},"relatedVulnerabilities":[{"id":"CVE-2026-83608","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83608","cwe":"CWE-91","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83608","date":"2026-10-08","epss":0.00612,"percentile":0.47677}],"urls":["https://github.com/xmldom/xmldom/commit/57aec90ac57b4408ae7c5d1746bf2a693b5ed90e","https://github.com/xmldom/xmldom/commit/85f12eb4d14b44de33216cfb72b50af4d24e9fdd","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12","https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83608","description":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing > or whitespace can terminate the <!DOCTYPE ...> declaration and inject sibling markup; the value can be supplied through createDocumentType() on the 0.8.x and unscoped lines or through a direct DocumentType.name property write on every affected line. The default path and legacy creation-time behavior remain permissive, while the vulnerable strict path fails to enforce an XML Name. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom."}]},{"artifact":{"id":"d15158c33cd9e623","cpes":["cpe:2.3:a:\\@xmldom\\/xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*","cpe:2.3:a:xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*"],"name":"@xmldom/xmldom","purl":"pkg:npm/%40xmldom/xmldom@0.8.14","type":"npm","version":"0.8.14","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.8.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c7q8-3ch8-vqpv","versionConstraint":">=0.7.0,<=0.8.14 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@xmldom/xmldom","version":"0.8.14"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-c7q8-3ch8-vqpv","fix":{"state":"fixed","versions":["0.8.15"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"0.8.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83616","cwe":"CWE-91","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83616","date":"2026-10-08","epss":0.00612,"percentile":0.47677}],"risk":0.49571999999999994,"urls":["https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv","https://nvd.nist.gov/vuln/detail/CVE-2026-83616","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/commit/1cde3e31a07c41c87cfd368d6946aa477f16b4f9","https://github.com/xmldom/xmldom/commit/3b694872bcb5c7e3cbadba961a4be2488750ce5b","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c7q8-3ch8-vqpv","description":"xmldom: Processing Instruction Target Injection Bypasses requireWellFormed"},"relatedVulnerabilities":[{"id":"CVE-2026-83616","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83616","cwe":"CWE-91","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83616","date":"2026-10-08","epss":0.00612,"percentile":0.47677}],"urls":["https://github.com/xmldom/xmldom/commit/1cde3e31a07c41c87cfd368d6946aa477f16b4f9","https://github.com/xmldom/xmldom/commit/3b694872bcb5c7e3cbadba961a4be2488750ce5b","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12","https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83616","description":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createProcessingInstruction(target, data) in lib/dom.js accepts an unvalidated target, while the requireWellFormed: true serializer checks only for a colon and the reserved case-insensitive xml name on 0.9.x and performs no target check on 0.8.x. Because serialization emits <?target data?>, a target containing >, ?, whitespace, or another invalid XML-name character can break the processing-instruction boundary and inject XML structure. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom."}]},{"artifact":{"id":"bc71e82d5a3f822c","cpes":["cpe:2.3:a:source-map-js:source-map-js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:source-map-js:source_map_js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:source_map_js:source-map-js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:source_map_js:source_map_js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:source-map:source-map-js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:source-map:source_map_js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:source_map:source-map-js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:source_map:source_map_js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:7rulnik:source-map-js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:7rulnik:source_map_js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:source:source-map-js:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:source:source_map_js:1.2.1:*:*:*:*:*:*:*"],"name":"source-map-js","purl":"pkg:npm/source-map-js@1.2.1","type":"npm","version":"1.2.1","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/source-map-js@1.2.1/node_modules/source-map-js/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/source-map-js@1.2.1/node_modules/source-map-js/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.2.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-68fv-2mgg-jv7q","versionConstraint":">=1.0.0,<1.2.2 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"source-map-js","version":"1.2.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-68fv-2mgg-jv7q","fix":{"state":"fixed","versions":["1.2.2"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.2.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93749","cwe":"CWE-1284","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93749","date":"2026-10-08","epss":0.0063,"percentile":0.48554}],"risk":0.4914,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-93749","https://github.com/7rulnik/source-map-js/issues/76","https://github.com/7rulnik/source-map-js","https://github.com/7rulnik/source-map-js/blob/c1cd8904bb7bd0c7fb5879fcda48134d82a27934/lib/source-node.js#L115-L118","https://www.vulncheck.com/advisories/source-map-js-through-1.2.1-event-loop-denial-of-service","https://github.com/7rulnik/source-map-js/pull/79","https://github.com/7rulnik/source-map-js/commit/cf7658058ceeaa8619d5ae0ec90be6905209d016","https://github.com/7rulnik/source-map-js/releases/tag/v1.2.2"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-68fv-2mgg-jv7q","description":"source-map-js allows event-loop denial of service through indexed source-map section offsets"},"relatedVulnerabilities":[{"id":"CVE-2026-93749","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93749","cwe":"CWE-1284","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93749","date":"2026-10-08","epss":0.0063,"percentile":0.48554}],"urls":["https://github.com/7rulnik/source-map-js","https://github.com/7rulnik/source-map-js/blob/c1cd8904bb7bd0c7fb5879fcda48134d82a27934/lib/source-node.js#L115-L118","https://github.com/7rulnik/source-map-js/issues/76","https://www.vulncheck.com/advisories/source-map-js-through-1.2.1-event-loop-denial-of-service"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93749","description":"source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests."}]},{"artifact":{"id":"d15158c33cd9e623","cpes":["cpe:2.3:a:\\@xmldom\\/xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*","cpe:2.3:a:xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*"],"name":"@xmldom/xmldom","purl":"pkg:npm/%40xmldom/xmldom@0.8.14","type":"npm","version":"0.8.14","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.8.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8344-3jmq-59r6","versionConstraint":">=0.7.0,<=0.8.14 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@xmldom/xmldom","version":"0.8.14"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-8344-3jmq-59r6","fix":{"state":"fixed","versions":["0.8.15"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"0.8.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83613","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83613","date":"2026-10-08","epss":0.00604,"percentile":0.47252}],"risk":0.48924,"urls":["https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv","https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6","https://nvd.nist.gov/vuln/detail/CVE-2026-83613","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/commit/2c548f200cfec991cd5846627ef8f03542309213","https://github.com/xmldom/xmldom/commit/cfb09b5dbeb035fdfedc9f01e2bbaf226bf47cf3","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8344-3jmq-59r6","description":"xmldom: Quadratic-time attribute deduplication"},"relatedVulnerabilities":[{"id":"CVE-2026-83613","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83613","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83613","date":"2026-10-08","epss":0.00604,"percentile":0.47252}],"urls":["https://github.com/xmldom/xmldom/commit/2c548f200cfec991cd5846627ef8f03542309213","https://github.com/xmldom/xmldom/commit/cfb09b5dbeb035fdfedc9f01e2bbaf226bf47cf3","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12","https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6","https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83613","description":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMHandler.startElement in lib/dom-parser.js inserts every parsed attribute through setAttributeNode, while NamedNodeMap.setNamedItem in lib/dom.js calls the linear getNamedItem or getNamedItemNS lookup for each insertion. A well-formed element with many distinct attributes therefore requires quadratic comparisons during DOMParser.parseFromString() and can stall a Node.js event loop before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom."}]},{"artifact":{"id":"9b333847e4cf6c68","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.7:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.7","type":"npm","version":"5.0.7","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rgw5-rvv9-x895","versionConstraint":">=4.0.0,<5.0.9 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.7"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rgw5-rvv9-x895","fix":{"state":"fixed","versions":["5.0.9"],"available":[{"date":"2026-08-03","kind":"first-observed","version":"5.0.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69152","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69152","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69152","date":"2026-10-08","epss":0.00647,"percentile":0.49398}],"risk":0.48525,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895","https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d","https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac","https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031","https://nvd.nist.gov/vuln/detail/CVE-2026-69152"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rgw5-rvv9-x895","description":"brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation"},"relatedVulnerabilities":[{"id":"CVE-2026-69152","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69152","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69152","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69152","date":"2026-10-08","epss":0.00647,"percentile":0.49398}],"urls":["https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d","https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac","https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69152","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9."}]},{"artifact":{"id":"9b333847e4cf6c68","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.7:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.7","type":"npm","version":"5.0.7","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mh99-v99m-4gvg","versionConstraint":">=4.0.0,<5.0.8 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.7"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-mh99-v99m-4gvg","fix":{"state":"fixed","versions":["5.0.8"],"available":[{"date":"2026-07-25","kind":"first-observed","version":"5.0.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14257","cwe":"CWE-400","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"},{"cve":"CVE-2026-14257","cwe":"CWE-770","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"}],"epss":[{"cve":"CVE-2026-14257","date":"2026-10-08","epss":0.00643,"percentile":0.4921}],"risk":0.48225000000000007,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-mh99-v99m-4gvg","https://nvd.nist.gov/vuln/detail/CVE-2026-14257","https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5","https://github.com/juliangruber/brace-expansion","https://www.npmjs.com/package/brace-expansion","https://github.com/juliangruber/brace-expansion/pull/129","https://github.com/juliangruber/brace-expansion/pull/130","https://github.com/juliangruber/brace-expansion/pull/136","https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031","https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mh99-v99m-4gvg","description":"brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash"},"relatedVulnerabilities":[{"id":"CVE-2026-14257","cvss":[{"type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14257","cwe":"CWE-400","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"},{"cve":"CVE-2026-14257","cwe":"CWE-770","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"}],"epss":[{"cve":"CVE-2026-14257","date":"2026-10-08","epss":0.00643,"percentile":0.4921}],"urls":["https://github.com/juliangruber/brace-expansion","https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5","https://www.npmjs.com/package/brace-expansion"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14257","description":"brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays."}]},{"artifact":{"id":"d15158c33cd9e623","cpes":["cpe:2.3:a:\\@xmldom\\/xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*","cpe:2.3:a:xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*"],"name":"@xmldom/xmldom","purl":"pkg:npm/%40xmldom/xmldom@0.8.14","type":"npm","version":"0.8.14","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.8.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-93r5-fhx6-vmg9","versionConstraint":">=0.7.0,<=0.8.14 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@xmldom/xmldom","version":"0.8.14"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-93r5-fhx6-vmg9","fix":{"state":"fixed","versions":["0.8.15"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"0.8.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83614","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-83614","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83614","date":"2026-10-08","epss":0.0059,"percentile":0.46536}],"risk":0.47789999999999994,"urls":["https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9","https://nvd.nist.gov/vuln/detail/CVE-2026-83614","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/commit/0748720b620555f8c222782dcab575cf0cf403b4","https://github.com/xmldom/xmldom/commit/f40ccb861eee0acbf5ee4feb9a34932e87b329c9","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-93r5-fhx6-vmg9","description":"xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge"},"relatedVulnerabilities":[{"id":"CVE-2026-83614","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83614","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-83614","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83614","date":"2026-10-08","epss":0.0059,"percentile":0.46536}],"urls":["https://github.com/xmldom/xmldom/commit/0748720b620555f8c222782dcab575cf0cf403b4","https://github.com/xmldom/xmldom/commit/f40ccb861eee0acbf5ee4feb9a34932e87b329c9","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12","https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83614","description":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.3.0 through 0.6.0, two independent quadratic paths can cause denial of service. In lib/sax.js, parseElementStartPart repeatedly rescans a malformed tag name to the next > during single-character recovery; in lib/dom.js, normalize() repeatedly removes and appends adjacent text nodes, causing quadratic reindexing and string rebuilding. The first path is reachable through default DOMParser.parseFromString() processing, while the second is also reachable through a direct normalize() call on a programmatically constructed DOM, and endDocument invokes that normalization after parsing. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom."}]},{"artifact":{"id":"d15158c33cd9e623","cpes":["cpe:2.3:a:\\@xmldom\\/xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*","cpe:2.3:a:xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*"],"name":"@xmldom/xmldom","purl":"pkg:npm/%40xmldom/xmldom@0.8.14","type":"npm","version":"0.8.14","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.8.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-965w-775f-mr7g","versionConstraint":">=0.7.0,<=0.8.14 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@xmldom/xmldom","version":"0.8.14"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-965w-775f-mr7g","fix":{"state":"fixed","versions":["0.8.15"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"0.8.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83615","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83615","date":"2026-10-08","epss":0.0059,"percentile":0.46536}],"risk":0.47789999999999994,"urls":["https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g","https://nvd.nist.gov/vuln/detail/CVE-2026-83615","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/commit/954370f58c046223faf95ba77efcbc8ce014409d","https://github.com/xmldom/xmldom/commit/dabffe884e864eeecb1f515c716f875e1bc47ec1","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-965w-775f-mr7g","description":"xmldom: Quadratic-memory consumption"},"relatedVulnerabilities":[{"id":"CVE-2026-83615","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83615","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83615","date":"2026-10-08","epss":0.0059,"percentile":0.46536}],"urls":["https://github.com/xmldom/xmldom/commit/954370f58c046223faf95ba77efcbc8ce014409d","https://github.com/xmldom/xmldom/commit/dabffe884e864eeecb1f515c716f875e1bc47ec1","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12","https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83615","description":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _copy to clone the complete currentNSMap for each nested element that declares a new namespace prefix. Keeping every ancestor map live on the parse stack creates quadratic peak namespace-map storage, so a small highly compressible XML document can exhaust the process heap before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-54874"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-54874"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60000"},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60000"},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60000"},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60000"},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60000"},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60000"},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60000"},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"31a0e0e0d1265f89","cpes":["cpe:2.3:a:adm-zip_project:adm-zip:0.6.0:*:*:*:*:node.js:*:*"],"name":"adm-zip","purl":"pkg:npm/adm-zip@0.6.0","type":"npm","version":"0.6.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7q85-xj36-vmfc","versionConstraint":"<0.6.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"adm-zip","version":"0.6.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-7q85-xj36-vmfc","fix":{"state":"fixed","versions":["0.6.1"],"available":[{"date":"2026-09-19","kind":"first-observed","version":"0.6.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77301","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77301","date":"2026-10-08","epss":0.00609,"percentile":0.47541}],"risk":0.45675000000000004,"urls":["https://github.com/cthackers/adm-zip/security/advisories/GHSA-7q85-xj36-vmfc","https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6","https://github.com/cthackers/adm-zip/releases/tag/v0.6.1"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7q85-xj36-vmfc","description":"adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-77301","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77301","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77301","date":"2026-10-08","epss":0.00609,"percentile":0.47541}],"urls":["https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6","https://github.com/cthackers/adm-zip/releases/tag/v0.6.1","https://github.com/cthackers/adm-zip/security/advisories/GHSA-7q85-xj36-vmfc"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77301","description":"adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value against the actual compressed data and decompression result. A small crafted ZIP can declare a multi-gigabyte uncompressed size, causing Buffer.alloc and decompression handling to commit excessive resident memory before CRC validation reports an error. Applications that read entries from untrusted archives can therefore be terminated by the operating system or suffer service-wide memory exhaustion. This issue is fixed in version 0.6.1."}]},{"artifact":{"id":"1d01ad883d38833b","cpes":["cpe:2.3:a:BinaryMuse:toml:3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:toml:toml:3.0.0:*:*:*:*:*:*:*"],"name":"toml","purl":"pkg:npm/toml@3.0.0","type":"npm","version":"3.0.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/toml@3.0.0/node_modules/toml/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/toml@3.0.0/node_modules/toml/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.2.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-82x6-q7mm-w9cf","versionConstraint":"<4.2.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"toml","version":"3.0.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-82x6-q7mm-w9cf","fix":{"state":"fixed","versions":["4.2.0"],"available":[{"date":"2026-09-04","kind":"first-observed","version":"4.2.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77465","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77465","date":"2026-10-08","epss":0.00609,"percentile":0.47541}],"risk":0.45675000000000004,"urls":["https://github.com/BinaryMuse/toml-node/security/advisories/GHSA-82x6-q7mm-w9cf","https://github.com/BinaryMuse/toml-node/pull/72","https://github.com/BinaryMuse/toml-node/commit/967b8b06754f3ecd9863cea118dc50792a8c353f"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-82x6-q7mm-w9cf","description":"toml-node: Uncontrolled Recursion"},"relatedVulnerabilities":[{"id":"CVE-2026-77465","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77465","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77465","date":"2026-10-08","epss":0.00609,"percentile":0.47541}],"urls":["https://github.com/BinaryMuse/toml-node/commit/967b8b06754f3ecd9863cea118dc50792a8c353f","https://github.com/BinaryMuse/toml-node/pull/72","https://github.com/BinaryMuse/toml-node/security/advisories/GHSA-82x6-q7mm-w9cf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77465","description":"toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions recurse through nested arrays and inline tables without a depth limit. A remote unauthenticated application parsing an attacker-controlled TOML document containing a few thousand nested arrays or inline tables can exhaust the Node.js call stack, raise an unexpected RangeError rather than the parser's SyntaxError, and terminate an unprotected request worker or process. The corresponding grammar source is src/toml.pegjs, where the generated parser must be bounded. This issue is fixed in version 4.2.0."}]},{"artifact":{"id":"e4ab16c6d35e61b6","cpes":["cpe:2.3:a:compression:compression:1.8.1:*:*:*:*:*:*:*"],"name":"compression","purl":"pkg:npm/compression@1.8.1","type":"npm","version":"1.8.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/compression@1.8.1_supports-color@8.1.1/node_modules/compression/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/compression@1.8.1_supports-color@8.1.1/node_modules/compression/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vc2v-76pw-4v95","versionConstraint":"<1.8.2 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"compression","version":"1.8.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-vc2v-76pw-4v95","fix":{"state":"fixed","versions":["1.8.2"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.8.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87776","cwe":"CWE-401","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-87776","cwe":"CWE-459","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-87776","date":"2026-10-08","epss":0.00608,"percentile":0.47444}],"risk":0.45599999999999996,"urls":["https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95","https://nvd.nist.gov/vuln/detail/CVE-2026-87776","https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff","https://cna.openjsf.org/security-advisories.html","https://github.com/expressjs/compression/releases/tag/v1.8.2"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vc2v-76pw-4v95","description":"compression vulnerable to Denial of Service via memory leak on premature response close"},"relatedVulnerabilities":[{"id":"CVE-2026-87776","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87776","cwe":"CWE-401","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-87776","cwe":"CWE-459","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-87776","date":"2026-10-08","epss":0.00608,"percentile":0.47444}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87776","description":"compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote unauthenticated attacker can repeatedly open requests and disconnect early, exhausting the available memory and crashing the server. All applications using compression are affected. The issue is fixed in compression 1.8.2, and users should upgrade to 1.8.2 or later."}]},{"artifact":{"id":"d15158c33cd9e623","cpes":["cpe:2.3:a:\\@xmldom\\/xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*","cpe:2.3:a:xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*"],"name":"@xmldom/xmldom","purl":"pkg:npm/%40xmldom/xmldom@0.8.14","type":"npm","version":"0.8.14","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.8.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x4fp-j954-r2f4","versionConstraint":">=0.7.0,<=0.8.14 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@xmldom/xmldom","version":"0.8.14"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-x4fp-j954-r2f4","fix":{"state":"fixed","versions":["0.8.15"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"0.8.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83619","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-83619","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83619","date":"2026-10-08","epss":0.00524,"percentile":0.42605}],"risk":0.42444,"urls":["https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4","https://nvd.nist.gov/vuln/detail/CVE-2026-83619","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/commit/3abb0934f5a8a84d83a1f9cde0f2bd04c08b2a09","https://github.com/xmldom/xmldom/releases/tag/0.8.15"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x4fp-j954-r2f4","description":"xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser"},"relatedVulnerabilities":[{"id":"CVE-2026-83619","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83619","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-83619","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83619","date":"2026-10-08","epss":0.00524,"percentile":0.42605}],"urls":["https://github.com/xmldom/xmldom/commit/3abb0934f5a8a84d83a1f9cde0f2bd04c08b2a09","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83619","description":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js trims captured end-tag names with the unanchored global expression /[ \\t\\n\\r]+$/g. For an end tag containing a long whitespace run followed by a non-whitespace character, the expression retries from each possible starting position and backtracks quadratically before failing its end anchor. DOMParser.parseFromString() reaches the path under default options, allowing a small unauthenticated XML input to stall the Node.js event loop; the 0.9.x and unscoped npm lines do not contain this expression. This issue is fixed in @xmldom/xmldom version 0.8.15."}]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-80229"},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"93f929590853fc8f","cpes":["cpe:2.3:a:showdownjs:showdown:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:showdown:showdown:2.1.0:*:*:*:*:*:*:*"],"name":"showdown","purl":"pkg:npm/showdown@2.1.0","type":"npm","version":"2.1.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/showdown@2.1.0/node_modules/showdown/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/showdown@2.1.0/node_modules/showdown/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rmmh-p597-ppvv","versionConstraint":"<=2.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"showdown","version":"2.1.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rmmh-p597-ppvv","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-1899","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-1899","date":"2026-10-08","epss":0.00806,"percentile":0.55485}],"risk":0.41509,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-1899","https://www.tenable.com/security/research/tra-2024-05"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rmmh-p597-ppvv","description":"Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing"},"relatedVulnerabilities":[{"id":"CVE-2024-1899","cvss":[{"type":"Secondary","source":"vulnreport@tenable.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-1899","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-1899","date":"2026-10-08","epss":0.00806,"percentile":0.55485}],"urls":["https://www.tenable.com/security/research/tra-2024-05"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-1899","description":"An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions."}]},{"artifact":{"id":"c87764051de550d7","cpes":["cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:4.2.0:*:*:*:*:node.js:*:*"],"name":"http-cache-semantics","purl":"pkg:npm/http-cache-semantics@4.2.0","type":"npm","version":"4.2.0","language":"javascript","licenses":["BSD-2-Clause"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/http-cache-semantics/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/http-cache-semantics/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ch52-4w7c-c8xp","versionConstraint":"<=4.2.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"http-cache-semantics","version":"4.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-ch52-4w7c-c8xp","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93748","cwe":"CWE-524","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93748","date":"2026-10-08","epss":0.00531,"percentile":0.43107}],"risk":0.41418,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-93748","https://github.com/kornelski/http-cache-semantics/issues/56","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L425-L441","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L603-L623","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-user-cache-disclosure-via-max-stale"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ch52-4w7c-c8xp","description":"http-cache-semantics max-stale handling can disclose cross-user cached responses"},"relatedVulnerabilities":[{"id":"CVE-2026-93748","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93748","cwe":"CWE-524","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93748","date":"2026-10-08","epss":0.00531,"percentile":0.43107}],"urls":["https://github.com/kornelski/http-cache-semantics","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L425-L441","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L603-L623","https://github.com/kornelski/http-cache-semantics/issues/56","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-user-cache-disclosure-via-max-stale"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93748","description":"http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons."}]},{"artifact":{"id":"83d3e58bdcd90e29","cpes":["cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:4.2.0:*:*:*:*:node.js:*:*"],"name":"http-cache-semantics","purl":"pkg:npm/http-cache-semantics@4.2.0","type":"npm","version":"4.2.0","language":"javascript","licenses":["BSD-2-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/http-cache-semantics/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/http-cache-semantics/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ch52-4w7c-c8xp","versionConstraint":"<=4.2.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"http-cache-semantics","version":"4.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-ch52-4w7c-c8xp","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93748","cwe":"CWE-524","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93748","date":"2026-10-08","epss":0.00531,"percentile":0.43107}],"risk":0.41418,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-93748","https://github.com/kornelski/http-cache-semantics/issues/56","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L425-L441","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L603-L623","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-user-cache-disclosure-via-max-stale"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ch52-4w7c-c8xp","description":"http-cache-semantics max-stale handling can disclose cross-user cached responses"},"relatedVulnerabilities":[{"id":"CVE-2026-93748","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93748","cwe":"CWE-524","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93748","date":"2026-10-08","epss":0.00531,"percentile":0.43107}],"urls":["https://github.com/kornelski/http-cache-semantics","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L425-L441","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L603-L623","https://github.com/kornelski/http-cache-semantics/issues/56","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-user-cache-disclosure-via-max-stale"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93748","description":"http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons."}]},{"artifact":{"id":"00147cddb3b052ad","cpes":["cpe:2.3:a:tar_project:tar:7.5.19:*:*:*:*:node.js:*:*","cpe:2.3:a:tar_project:tar:7.5.19:*:*:*:*:rust:*:*","cpe:2.3:a:isaacs:tar:7.5.19:*:*:*:*:node.js:*:*"],"name":"tar","purl":"pkg:npm/tar@7.5.19","type":"npm","version":"7.5.19","language":"javascript","licenses":["BlueOak-1.0.0"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/tar/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/tar/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r292-9mhp-454m","versionConstraint":"<=7.5.20 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"tar","version":"7.5.19"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-r292-9mhp-454m","fix":{"state":"fixed","versions":["7.5.21"],"available":[{"date":"2026-07-24","kind":"first-observed","version":"7.5.21"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73566","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-73566","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73566","date":"2026-10-08","epss":0.00531,"percentile":0.43086}],"risk":0.39825,"urls":["https://github.com/isaacs/node-tar/security/advisories/GHSA-r292-9mhp-454m","https://github.com/isaacs/node-tar/commit/631ae59121bf8fc8a22bbae35f074cb9b789cd4a","https://github.com/isaacs/node-tar/releases/tag/v7.5.21","https://nvd.nist.gov/vuln/detail/CVE-2026-73566"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r292-9mhp-454m","description":"node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection"},"relatedVulnerabilities":[{"id":"CVE-2026-73566","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73566","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-73566","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73566","date":"2026-10-08","epss":0.00531,"percentile":0.43086}],"urls":["https://github.com/isaacs/node-tar/commit/631ae59121bf8fc8a22bbae35f074cb9b789cd4a","https://github.com/isaacs/node-tar/security/advisories/GHSA-r292-9mhp-454m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73566","description":"node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filter(entry.path, entry) in Parser[CONSUMEHEADER] in src/parse.ts before Unpack[CHECKPATH] applies maxDepth, causing an uncatchable RangeError stack overflow that terminates asynchronous and streaming Node.js consumers. This issue is fixed in version 7.5.21."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pq3-5fj3-cg6v","versionConstraint":">=1.13.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3pq3-5fj3-cg6v","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101898","cwe":"CWE-918","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101898","date":"2026-10-08","epss":0.00527,"percentile":0.42847}],"risk":0.38207500000000005,"urls":["https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v","https://nvd.nist.gov/vuln/detail/CVE-2026-101898","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pq3-5fj3-cg6v","description":"Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls"},"relatedVulnerabilities":[{"id":"CVE-2026-101898","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101898","cwe":"CWE-918","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101898","date":"2026-10-08","epss":0.00527,"percentile":0.42847}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101898","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-derived proxy settings, or relies on caller-supplied config.lookup DNS policy. The HTTP/2 path can connect without the configured proxy behavior or without applying the caller-supplied config.lookup policy before http2.connect(). Requests can bypass the intended proxy route or the caller-supplied DNS resolution policy. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pq3-5fj3-cg6v","versionConstraint":">=1.13.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3pq3-5fj3-cg6v","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101898","cwe":"CWE-918","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101898","date":"2026-10-08","epss":0.00527,"percentile":0.42847}],"risk":0.38207500000000005,"urls":["https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v","https://nvd.nist.gov/vuln/detail/CVE-2026-101898","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pq3-5fj3-cg6v","description":"Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls"},"relatedVulnerabilities":[{"id":"CVE-2026-101898","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101898","cwe":"CWE-918","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101898","date":"2026-10-08","epss":0.00527,"percentile":0.42847}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101898","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-derived proxy settings, or relies on caller-supplied config.lookup DNS policy. The HTTP/2 path can connect without the configured proxy behavior or without applying the caller-supplied config.lookup policy before http2.connect(). Requests can bypass the intended proxy route or the caller-supplied DNS resolution policy. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"bb3bb0d123bb84ee","cpes":["cpe:2.3:a:handlebars.js_project:handlebars.js:4.7.9:*:*:*:*:node.js:*:*","cpe:2.3:a:handlebarsjs:handlebars:4.7.9:*:*:*:*:node.js:*:*"],"name":"handlebars","purl":"pkg:npm/handlebars@4.7.9","type":"npm","version":"4.7.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/handlebars@4.7.9/node_modules/handlebars/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/handlebars@4.7.9/node_modules/handlebars/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.7.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p8wg-vrv2-v86f","versionConstraint":">=4.0.0,<=4.7.9 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"handlebars","version":"4.7.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-p8wg-vrv2-v86f","fix":{"state":"fixed","versions":["4.7.10"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"4.7.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106445","cwe":"CWE-184","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106445","cwe":"CWE-1289","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106445","date":"2026-10-08","epss":0.00411,"percentile":0.33314}],"risk":0.37400999999999995,"urls":["https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-p8wg-vrv2-v86f","https://nvd.nist.gov/vuln/detail/CVE-2026-106445","https://github.com/handlebars-lang/handlebars.js/pull/2185","https://github.com/handlebars-lang/handlebars.js/commit/ceec388abe1d1aac8f6369860d5f390fa71ef4fa","https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10"],"severity":"Critical","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p8wg-vrv2-v86f","description":"Handlebars: JavaScript Injection via Own Property Check Bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-106445","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106445","cwe":"CWE-184","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106445","cwe":"CWE-1289","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106445","date":"2026-10-08","epss":0.00411,"percentile":0.33314}],"urls":["https://github.com/handlebars-lang/handlebars.js/commit/ceec388abe1d1aac8f6369860d5f390fa71ef4fa","https://github.com/handlebars-lang/handlebars.js/pull/2185","https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10","https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-p8wg-vrv2-v86f"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106445","description":"Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10."}]},{"artifact":{"id":"d15158c33cd9e623","cpes":["cpe:2.3:a:\\@xmldom\\/xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*","cpe:2.3:a:xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*"],"name":"@xmldom/xmldom","purl":"pkg:npm/%40xmldom/xmldom@0.8.14","type":"npm","version":"0.8.14","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.8.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6h8r-xr42-gp59","versionConstraint":">=0.7.0,<=0.8.14 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@xmldom/xmldom","version":"0.8.14"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6h8r-xr42-gp59","fix":{"state":"fixed","versions":["0.8.15"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"0.8.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83611","cwe":"CWE-1286","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83611","date":"2026-10-08","epss":0.00619,"percentile":0.48059}],"risk":0.368305,"urls":["https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59","https://nvd.nist.gov/vuln/detail/CVE-2026-83611","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/commit/4430189660b0d380ee9c9ee7550a1358688e8828","https://github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6h8r-xr42-gp59","description":"xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content"},"relatedVulnerabilities":[{"id":"CVE-2026-83611","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83611","cwe":"CWE-1286","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83611","date":"2026-10-08","epss":0.00619,"percentile":0.48059}],"urls":["https://github.com/xmldom/xmldom/commit/4430189660b0d380ee9c9ee7550a1358688e8828","https://github.com/xmldom/xmldom/commit/7b2ec67e1750daadd0bb06c92e875e726544a362","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12","https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83611","description":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMParser.parseFromString() can silently accept an end tag such as </a\\njunk>, close the element, and discard the trailing content. On 0.9.x, the lib/sax.js end-tag validator inherits the multiline flag from reg(), allowing the first line to satisfy the anchored XML ETag production; older lines have no equivalent residue validation. This parser differential can bypass a parse-before-trust well-formedness gate, although it does not inject the discarded content; onError on 0.9.x and errorHandler on 0.8.x are the relevant reporting interfaces. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom."}]},{"artifact":{"id":"3b8f27c62542446d","cpes":["cpe:2.3:a:markdown-it_project:markdown-it:13.0.2:*:*:*:*:*:*:*"],"name":"markdown-it","purl":"pkg:npm/markdown-it@13.0.2","type":"npm","version":"13.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/markdown-it@13.0.2/node_modules/markdown-it/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/markdown-it@13.0.2/node_modules/markdown-it/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"14.1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-38c4-r59v-3vqw","versionConstraint":">=13.0.0,<14.1.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"markdown-it","version":"13.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-38c4-r59v-3vqw","fix":{"state":"fixed","versions":["14.1.1"],"available":[{"date":"2026-03-04","kind":"first-observed","version":"14.1.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":5.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2327","cwe":"CWE-1333","type":"Secondary","source":"report@snyk.io"}],"epss":[{"cve":"CVE-2026-2327","date":"2026-10-08","epss":0.00691,"percentile":0.51341}],"risk":0.35932000000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-2327","https://github.com/markdown-it/markdown-it/commit/4b4bbcae5e0990a5b172378e507b33a59012ed26","https://gist.github.com/ltduc147/c9abecae1b291ede4f692f2ab988c917","https://security.snyk.io/vuln/SNYK-JS-MARKDOWNIT-10666750","https://github.com/markdown-it/markdown-it/blob/14.1.0/lib/rules_inline/linkify.mjs#L33"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-38c4-r59v-3vqw","description":"markdown-it is has a Regular Expression Denial of Service (ReDoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-2327","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2327","cwe":"CWE-1333","type":"Secondary","source":"report@snyk.io"}],"epss":[{"cve":"CVE-2026-2327","date":"2026-10-08","epss":0.00691,"percentile":0.51341}],"urls":["https://gist.github.com/ltduc147/c9abecae1b291ede4f692f2ab988c917","https://github.com/markdown-it/markdown-it/blob/14.1.0/lib/rules_inline/linkify.mjs%23L33","https://github.com/markdown-it/markdown-it/commit/4b4bbcae5e0990a5b172378e507b33a59012ed26","https://security.snyk.io/vuln/SNYK-JS-MARKDOWNIT-10666750"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2327","description":"Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition."}]},{"artifact":{"id":"759d8a1cdfa5f282","cpes":["cpe:2.3:a:simple-git_project:simple-git:3.36.0:*:*:*:*:node.js:*:*"],"name":"simple-git","purl":"pkg:npm/simple-git@3.36.0","type":"npm","version":"3.36.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/simple-git@3.36.0_supports-color@8.1.1/node_modules/simple-git/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/simple-git@3.36.0_supports-color@8.1.1/node_modules/simple-git/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g4wm-2vf7-vfgr","versionConstraint":"<=3.36.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"simple-git","version":"3.36.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-g4wm-2vf7-vfgr","fix":{"state":"fixed","versions":["4.0.0"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"4.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102826","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102826","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102826","date":"2026-10-08","epss":0.0046,"percentile":0.37848}],"risk":0.3588,"urls":["https://github.com/steveukx/git-js/security/advisories/GHSA-g4wm-2vf7-vfgr","https://nvd.nist.gov/vuln/detail/CVE-2026-102826","https://github.com/steveukx/git-js/pull/1193","https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g4wm-2vf7-vfgr","description":"simple-git allows command execution through unblocked Git configuration includes"},"relatedVulnerabilities":[{"id":"CVE-2026-102826","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102826","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102826","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102826","date":"2026-10-08","epss":0.0046,"percentile":0.37848}],"urls":["https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7","https://github.com/steveukx/git-js/pull/1193","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.0","https://github.com/steveukx/git-js/security/advisories/GHSA-g4wm-2vf7-vfgr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102826","description":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and the initial remediation does not cover includeIf.<condition>.path, allowing the same file-loading primitive through a conditional include. A loaded configuration can set an executable Git option such as core.sshCommand, which Git invokes during the clone operation with the privileges of the Node.js process. Exploitation requires the application to pass attacker-influenced custom arguments and requires an attacker-controlled file that the process can read. This issue is fixed in 4.0.0."}]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-80255"},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-13608"},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"5da17db7f668f4cf","cpes":["cpe:2.3:a:shell-quote_project:shell-quote:1.9.0:*:*:*:*:node.js:*:*"],"name":"shell-quote","purl":"pkg:npm/shell-quote@1.9.0","type":"npm","version":"1.9.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/shell-quote@1.9.0/node_modules/shell-quote/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/shell-quote@1.9.0/node_modules/shell-quote/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-pqg4-j6r4-53mv","versionConstraint":">=1.8.4,<1.11.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"shell-quote","version":"1.9.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-pqg4-j6r4-53mv","fix":{"state":"fixed","versions":["1.11.0"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.11.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102422","cwe":"CWE-78","type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"}],"epss":[{"cve":"CVE-2026-102422","date":"2026-10-08","epss":0.00383,"percentile":0.30165}],"risk":0.3379975,"urls":["https://github.com/ljharb/shell-quote/security/advisories/GHSA-pqg4-j6r4-53mv","https://nvd.nist.gov/vuln/detail/CVE-2026-102422","https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc"],"severity":"Critical","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-pqg4-j6r4-53mv","description":"shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token"},"relatedVulnerabilities":[{"id":"CVE-2026-102422","cvss":[{"type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102422","cwe":"CWE-78","type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"}],"epss":[{"cve":"CVE-2026-102422","date":"2026-10-08","epss":0.00383,"percentile":0.30165}],"urls":["https://github.com/ljharb/shell-quote","https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc","https://github.com/ljharb/shell-quote/security/advisories/GHSA-pqg4-j6r4-53mv","https://www.npmjs.com/package/shell-quote"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102422","description":"shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\\n, \\r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is parsed as shell input: `quote(['echo', 'ok', { comment: 'x' }, 'a\\nid;#'])` runs `id` in sh, bash, dash, ksh and zsh. `parse()` emits a comment token for a `#` in the middle of a word (for example `http://example.com/#frag`), so callers that combine `parse()` output with another untrusted string, such as `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected. The fix for CVE-2026-9277 rejected line terminators in the comment's own text, but not in the tokens after it. Fixed in 1.11.0: `quote()` throws a `TypeError` when a string after a `{ comment }` token contains a line terminator."}]},{"artifact":{"id":"d15158c33cd9e623","cpes":["cpe:2.3:a:\\@xmldom\\/xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*","cpe:2.3:a:xmldom:\\@xmldom\\/xmldom:0.8.14:*:*:*:*:*:*:*"],"name":"@xmldom/xmldom","purl":"pkg:npm/%40xmldom/xmldom@0.8.14","type":"npm","version":"0.8.14","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@xmldom+xmldom@0.8.14/node_modules/@xmldom/xmldom/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.8.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6gmq-8vp8-gcm6","versionConstraint":">=0.7.0,<=0.8.14 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@xmldom/xmldom","version":"0.8.14"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6gmq-8vp8-gcm6","fix":{"state":"fixed","versions":["0.8.15"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"0.8.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83610","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83610","date":"2026-10-08","epss":0.0059,"percentile":0.46536}],"risk":0.33335,"urls":["https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6","https://nvd.nist.gov/vuln/detail/CVE-2026-83610","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/commit/4664386e4f4d99d17b416a151dbe8323e245284b","https://github.com/xmldom/xmldom/commit/6c3fb5ffeafe7901ec928ce9010988dd716c94a0","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6gmq-8vp8-gcm6","description":"xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization"},"relatedVulnerabilities":[{"id":"CVE-2026-83610","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83610","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-83610","date":"2026-10-08","epss":0.0059,"percentile":0.46536}],"urls":["https://github.com/xmldom/xmldom/commit/4664386e4f4d99d17b416a151dbe8323e245284b","https://github.com/xmldom/xmldom/commit/6c3fb5ffeafe7901ec928ce9010988dd716c94a0","https://github.com/xmldom/xmldom/pull/1071","https://github.com/xmldom/xmldom/pull/1072","https://github.com/xmldom/xmldom/releases/tag/0.8.15","https://github.com/xmldom/xmldom/releases/tag/0.9.12","https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83610","description":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom."}]},{"artifact":{"id":"419bb9cfaac3bb02","cpes":["cpe:2.3:a:libexpat:libexpat:2.8.3-r1:*:*:*:*:*:*:*"],"name":"libexpat","purl":"pkg:apk/alpine/libexpat@2.8.3-r1?arch=x86_64&distro=alpine-3.24&upstream=expat","type":"apk","version":"2.8.3-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libexpat.so.1"},{"path":"/usr/lib/libexpat.so.1.12.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"expat"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.8.5-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"< 2.8.5-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"expat","version":"2.8.3-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"fixed","versions":["2.8.5-r0"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"2.8.5-r0"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.32642999999999994,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-93990"},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4hqw-qxg8-jxx2","versionConstraint":">=1.12.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-4hqw-qxg8-jxx2","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101900","cwe":"CWE-74","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101900","cwe":"CWE-693","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101900","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101900","date":"2026-10-08","epss":0.00546,"percentile":0.44006}],"risk":0.32487,"urls":["https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2","https://nvd.nist.gov/vuln/detail/CVE-2026-101900","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4hqw-qxg8-jxx2","description":"Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders"},"relatedVulnerabilities":[{"id":"CVE-2026-101900","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101900","cwe":"CWE-74","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101900","cwe":"CWE-693","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101900","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101900","date":"2026-10-08","epss":0.00546,"percentile":0.44006}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101900","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or non-plain class instance whose inherited properties make it appear FormData-like; plain objects are blocked. The inherited getHeaders function can return attacker-controlled headers that resolveConfig merges into a fetch adapter request. Attacker-controlled headers can alter authorization, cache, metadata-service, or application-specific request behavior. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4hqw-qxg8-jxx2","versionConstraint":">=1.12.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-4hqw-qxg8-jxx2","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101900","cwe":"CWE-74","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101900","cwe":"CWE-693","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101900","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101900","date":"2026-10-08","epss":0.00546,"percentile":0.44006}],"risk":0.32487,"urls":["https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2","https://nvd.nist.gov/vuln/detail/CVE-2026-101900","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4hqw-qxg8-jxx2","description":"Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders"},"relatedVulnerabilities":[{"id":"CVE-2026-101900","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101900","cwe":"CWE-74","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101900","cwe":"CWE-693","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101900","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101900","date":"2026-10-08","epss":0.00546,"percentile":0.44006}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101900","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or non-plain class instance whose inherited properties make it appear FormData-like; plain objects are blocked. The inherited getHeaders function can return attacker-controlled headers that resolveConfig merges into a fetch adapter request. Attacker-controlled headers can alter authorization, cache, metadata-service, or application-specific request behavior. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63074"},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63074"},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mghh-pgcx-3jjj","versionConstraint":">=1.15.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-mghh-pgcx-3jjj","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101906","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101906","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101906","date":"2026-10-08","epss":0.00402,"percentile":0.32287}],"risk":0.31557,"urls":["https://github.com/axios/axios/security/advisories/GHSA-mghh-pgcx-3jjj","https://nvd.nist.gov/vuln/detail/CVE-2026-101906","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mghh-pgcx-3jjj","description":"Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location"},"relatedVulnerabilities":[{"id":"CVE-2026-101906","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101906","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101906","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101906","date":"2026-10-08","epss":0.00402,"percentile":0.32287}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-mghh-pgcx-3jjj"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101906","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect hostnames. HTTP_PROXY or HTTPS_PROXY is configured, NO_PROXY or no_proxy is non-empty, redirects are followed, and a crafted redirect Location contains many dots followed by a non-dot character. Hostname.replace(/.+$/, '') backtracks quadratically while processing the crafted redirect hostname. Synchronous regular-expression processing can block the Node.js event loop and cause denial of service. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mghh-pgcx-3jjj","versionConstraint":">=1.15.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-mghh-pgcx-3jjj","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101906","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101906","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101906","date":"2026-10-08","epss":0.00402,"percentile":0.32287}],"risk":0.31557,"urls":["https://github.com/axios/axios/security/advisories/GHSA-mghh-pgcx-3jjj","https://nvd.nist.gov/vuln/detail/CVE-2026-101906","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mghh-pgcx-3jjj","description":"Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location"},"relatedVulnerabilities":[{"id":"CVE-2026-101906","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101906","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101906","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101906","date":"2026-10-08","epss":0.00402,"percentile":0.32287}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-mghh-pgcx-3jjj"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101906","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect hostnames. HTTP_PROXY or HTTPS_PROXY is configured, NO_PROXY or no_proxy is non-empty, redirects are followed, and a crafted redirect Location contains many dots followed by a non-dot character. Hostname.replace(/.+$/, '') backtracks quadratically while processing the crafted redirect hostname. Synchronous regular-expression processing can block the Node.js event loop and cause denial of service. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"afa69f01b5a5aaac","cpes":["cpe:2.3:a:pcre2:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.47-r1:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.47-r1?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.47-r1","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.15.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.7"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"fixed","versions":["10.48-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"10.48-r0"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.30928999999999995,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82208","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-82208","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82208","date":"2026-10-08","epss":0.00407,"percentile":0.3292}],"risk":0.30524999999999997,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-82208"},"relatedVulnerabilities":[{"id":"CVE-2026-82208","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82208","date":"2026-10-08","epss":0.00407,"percentile":0.3292}],"urls":["https://curl.se/docs/CVE-2026-82208.html","https://curl.se/docs/CVE-2026-82208.json","https://hackerone.com/reports/3973090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82208","description":"With the wolfSSL backend, when CA caching is enabled and an\n`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can\nsilently reinstall the cached store after the callback returns. A certificate\ntrusted by the cached store but rejected by the callback-selected store is\nthen incorrectly accepted."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-542g-h47m-68v8","versionConstraint":">=1.13.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-542g-h47m-68v8","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101901","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101901","date":"2026-10-08","epss":0.00384,"percentile":0.303}],"risk":0.30144,"urls":["https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8","https://nvd.nist.gov/vuln/detail/CVE-2026-101901","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-542g-h47m-68v8","description":"Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization"},"relatedVulnerabilities":[{"id":"CVE-2026-101901","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101901","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101901","date":"2026-10-08","epss":0.00384,"percentile":0.303}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101901","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-542g-h47m-68v8","versionConstraint":">=1.13.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-542g-h47m-68v8","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101901","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101901","date":"2026-10-08","epss":0.00384,"percentile":0.303}],"risk":0.30144,"urls":["https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8","https://nvd.nist.gov/vuln/detail/CVE-2026-101901","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-542g-h47m-68v8","description":"Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization"},"relatedVulnerabilities":[{"id":"CVE-2026-101901","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101901","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101901","date":"2026-10-08","epss":0.00384,"percentile":0.303}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101901","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"e8c23e074f43a88c","cpes":["cpe:2.3:a:proxy-addr:proxy-addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy-addr:proxy_addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy_addr:proxy-addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy_addr:proxy_addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy:proxy-addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy:proxy_addr:2.0.7:*:*:*:*:*:*:*"],"name":"proxy-addr","purl":"pkg:npm/proxy-addr@2.0.7","type":"npm","version":"2.0.7","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/proxy-addr@2.0.7/node_modules/proxy-addr/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/proxy-addr@2.0.7/node_modules/proxy-addr/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.0.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jqcg-44mw-7w3h","versionConstraint":">=1.1.0,<2.0.8 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"proxy-addr","version":"2.0.7"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-jqcg-44mw-7w3h","fix":{"state":"fixed","versions":["2.0.8"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"2.0.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90711","cwe":"CWE-290","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-90711","cwe":"CWE-348","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-90711","cwe":"CWE-697","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-90711","date":"2026-10-08","epss":0.00332,"percentile":0.24353}],"risk":0.30046,"urls":["https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h","https://nvd.nist.gov/vuln/detail/CVE-2026-90711","https://github.com/jshttp/proxy-addr/commit/780911d84d18e2c5fa008ed0c0d387631ec11965","https://cna.openjsf.org/security-advisories.html","https://github.com/jshttp/proxy-addr/releases/tag/v2.0.8"],"severity":"Critical","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jqcg-44mw-7w3h","description":"proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet"},"relatedVulnerabilities":[{"id":"CVE-2026-90711","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90711","cwe":"CWE-290","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-90711","cwe":"CWE-348","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-90711","cwe":"CWE-697","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-90711","date":"2026-10-08","epss":0.00332,"percentile":0.24353}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90711","description":"proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet rather than the block it names. Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit logging. This is a fail-open regression introduced in version 1.1.0. The issue is fixed in proxy-addr 2.0.8, and users should upgrade to 2.0.8 or later. As a workaround, ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r4gj-5m52-g5wh","versionConstraint":">=1.17.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-r4gj-5m52-g5wh","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101907","cwe":"CWE-441","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101907","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101907","date":"2026-10-08","epss":0.00414,"percentile":0.33636}],"risk":0.3001499999999999,"urls":["https://github.com/axios/axios/security/advisories/GHSA-r4gj-5m52-g5wh","https://nvd.nist.gov/vuln/detail/CVE-2026-101907","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r4gj-5m52-g5wh","description":"Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF"},"relatedVulnerabilities":[{"id":"CVE-2026-101907","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101907","cwe":"CWE-441","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101907","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101907","date":"2026-10-08","epss":0.00414,"percentile":0.33636}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-r4gj-5m52-g5wh"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101907","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r4gj-5m52-g5wh","versionConstraint":">=1.17.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-r4gj-5m52-g5wh","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101907","cwe":"CWE-441","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101907","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101907","date":"2026-10-08","epss":0.00414,"percentile":0.33636}],"risk":0.3001499999999999,"urls":["https://github.com/axios/axios/security/advisories/GHSA-r4gj-5m52-g5wh","https://nvd.nist.gov/vuln/detail/CVE-2026-101907","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r4gj-5m52-g5wh","description":"Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF"},"relatedVulnerabilities":[{"id":"CVE-2026-101907","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101907","cwe":"CWE-441","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101907","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101907","date":"2026-10-08","epss":0.00414,"percentile":0.33636}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-r4gj-5m52-g5wh"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101907","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c29m-xwm3-cm6r","versionConstraint":">=1.16.1,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-c29m-xwm3-cm6r","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101903","cwe":"CWE-1333","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101903","date":"2026-10-08","epss":0.00382,"percentile":0.30161}],"risk":0.29986999999999997,"urls":["https://github.com/axios/axios/security/advisories/GHSA-c29m-xwm3-cm6r","https://nvd.nist.gov/vuln/detail/CVE-2026-101903","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c29m-xwm3-cm6r","description":"Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-101903","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101903","cwe":"CWE-1333","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101903","date":"2026-10-08","epss":0.00382,"percentile":0.30161}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-c29m-xwm3-cm6r"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101903","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service. The affected identifiers are fromDataURI, DATA_URL_PATTERN, data:. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c29m-xwm3-cm6r","versionConstraint":">=1.16.1,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-c29m-xwm3-cm6r","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101903","cwe":"CWE-1333","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101903","date":"2026-10-08","epss":0.00382,"percentile":0.30161}],"risk":0.29986999999999997,"urls":["https://github.com/axios/axios/security/advisories/GHSA-c29m-xwm3-cm6r","https://nvd.nist.gov/vuln/detail/CVE-2026-101903","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c29m-xwm3-cm6r","description":"Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-101903","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101903","cwe":"CWE-1333","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101903","date":"2026-10-08","epss":0.00382,"percentile":0.30161}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-c29m-xwm3-cm6r"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101903","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service. The affected identifiers are fromDataURI, DATA_URL_PATTERN, data:. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"d601a8f22159af10","cpes":["cpe:2.3:a:nodejs:undici:6.27.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.27.0","type":"npm","version":"6.27.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rfgv-xxqx-mfg5","versionConstraint":">=6.7.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.27.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rfgv-xxqx-mfg5","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-08","epss":0.00394,"percentile":0.31457}],"risk":0.29550000000000004,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5","https://nvd.nist.gov/vuln/detail/CVE-2026-19534","https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5","https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728","https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rfgv-xxqx-mfg5","description":"undici vulnerable to Denial of Service via unrequested WebSocket subprotocol"},"relatedVulnerabilities":[{"id":"CVE-2026-19534","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-08","epss":0.00394,"percentile":0.31457}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19534","description":"undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"1b9771ed454c8ce9","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rfgv-xxqx-mfg5","versionConstraint":">=6.7.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rfgv-xxqx-mfg5","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-08","epss":0.00394,"percentile":0.31457}],"risk":0.29550000000000004,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5","https://nvd.nist.gov/vuln/detail/CVE-2026-19534","https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5","https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728","https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rfgv-xxqx-mfg5","description":"undici vulnerable to Denial of Service via unrequested WebSocket subprotocol"},"relatedVulnerabilities":[{"id":"CVE-2026-19534","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-08","epss":0.00394,"percentile":0.31457}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19534","description":"undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"fae15e6d4c5e7e92","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/undici@6.28.0/node_modules/undici/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/undici@6.28.0/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rfgv-xxqx-mfg5","versionConstraint":">=6.7.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rfgv-xxqx-mfg5","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-08","epss":0.00394,"percentile":0.31457}],"risk":0.29550000000000004,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5","https://nvd.nist.gov/vuln/detail/CVE-2026-19534","https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5","https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728","https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rfgv-xxqx-mfg5","description":"undici vulnerable to Denial of Service via unrequested WebSocket subprotocol"},"relatedVulnerabilities":[{"id":"CVE-2026-19534","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-08","epss":0.00394,"percentile":0.31457}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19534","description":"undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-82209"},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"34a0a5e3ece0fdd0","cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:tiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:tiff:4.7.1-r0:*:*:*:*:*:*:*"],"name":"tiff","purl":"pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"4.7.1-r0","language":"","licenses":["libtiff"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libtiff.so.6"},{"path":"/usr/lib/libtiff.so.6.2.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"tiff"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.7.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4775","versionConstraint":"< 4.7.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"4.7.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4775","versionConstraint":"< 4.7.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-4775","fix":{"state":"fixed","versions":["4.7.2-r0"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"4.7.2-r0"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4775","date":"2026-10-08","epss":0.00375,"percentile":0.29323}],"risk":0.286875,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-4775"},"relatedVulnerabilities":[{"id":"CVE-2026-4775","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4775","date":"2026-10-08","epss":0.00375,"percentile":0.29323}],"urls":["https://access.redhat.com/errata/RHSA-2026:12265","https://access.redhat.com/errata/RHSA-2026:12271","https://access.redhat.com/errata/RHSA-2026:14929","https://access.redhat.com/errata/RHSA-2026:16055","https://access.redhat.com/errata/RHSA-2026:19150","https://access.redhat.com/errata/RHSA-2026:19363","https://access.redhat.com/errata/RHSA-2026:19585","https://access.redhat.com/errata/RHSA-2026:19586","https://access.redhat.com/errata/RHSA-2026:19604","https://access.redhat.com/errata/RHSA-2026:19608","https://access.redhat.com/errata/RHSA-2026:19609","https://access.redhat.com/errata/RHSA-2026:19657","https://access.redhat.com/errata/RHSA-2026:19659","https://access.redhat.com/errata/RHSA-2026:19702","https://access.redhat.com/errata/RHSA-2026:20583","https://access.redhat.com/errata/RHSA-2026:20585","https://access.redhat.com/errata/RHSA-2026:20591","https://access.redhat.com/errata/RHSA-2026:20592","https://access.redhat.com/errata/RHSA-2026:24992","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:25910","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:30349","https://access.redhat.com/errata/RHSA-2026:33388","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-4775","https://bugzilla.redhat.com/show_bug.cgi?id=2450768","https://lists.debian.org/debian-lts-announce/2026/04/msg00016.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4775.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4775","description":"A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution."}]},{"artifact":{"id":"419bb9cfaac3bb02","cpes":["cpe:2.3:a:libexpat:libexpat:2.8.3-r1:*:*:*:*:*:*:*"],"name":"libexpat","purl":"pkg:apk/alpine/libexpat@2.8.3-r1?arch=x86_64&distro=alpine-3.24&upstream=expat","type":"apk","version":"2.8.3-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libexpat.so.1"},{"path":"/usr/lib/libexpat.so.1.12.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"expat"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.8.4-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76641","versionConstraint":"< 2.8.4-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"expat","version":"2.8.3-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-76641","fix":{"state":"fixed","versions":["2.8.4-r0"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"2.8.4-r0"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76641","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76641","date":"2026-10-08","epss":0.00353,"percentile":0.26927}],"risk":0.28593,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-76641"},"relatedVulnerabilities":[{"id":"CVE-2026-76641","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76641","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76641","date":"2026-10-08","epss":0.00353,"percentile":0.26927}],"urls":["https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf","https://github.com/libexpat/libexpat/pull/1331","https://www.vulncheck.com/advisories/expat-out-of-bounds-read-via-dtdcopy"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76641","description":"Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046."}]},{"artifact":{"id":"5e2ab97b23f852fa","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.2.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.2.0","type":"npm","version":"10.2.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.2.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4xrf-jv44-h6hh","versionConstraint":">=10.1.1,<=10.2.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-4xrf-jv44-h6hh","fix":{"state":"fixed","versions":["10.2.2"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"10.2.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69198","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69198","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69198","date":"2026-10-08","epss":0.0048,"percentile":0.39448}],"risk":0.28559999999999997,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh","https://github.com/beaugunderson/ip-address/commit/488fe9bc7c35363b4b090494fc38c266d217740d","https://github.com/beaugunderson/ip-address/releases/tag/v10.2.2"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4xrf-jv44-h6hh","description":"ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks"},"relatedVulnerabilities":[{"id":"CVE-2026-69198","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69198","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69198","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69198","date":"2026-10-08","epss":0.0048,"percentile":0.39448}],"urls":["https://github.com/beaugunderson/ip-address/commit/488fe9bc7c35363b4b090494fc38c266d217740d","https://github.com/beaugunderson/ip-address/releases/tag/v10.2.2","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69198","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2."}]},{"artifact":{"id":"9f5ce00623e7a21a","cpes":["cpe:2.3:a:openjsf:fast-uri:3.1.6:*:*:*:*:node.js:*:*"],"name":"fast-uri","purl":"pkg:npm/fast-uri@3.1.6","type":"npm","version":"3.1.6","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/fast-uri@3.1.6/node_modules/fast-uri/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/fast-uri@3.1.6/node_modules/fast-uri/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-58mr-gqgx-xq4g","versionConstraint":"=3.1.6 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"fast-uri","version":"3.1.6"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-58mr-gqgx-xq4g","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84394","cwe":"CWE-436","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-84394","date":"2026-10-08","epss":0.0038,"percentile":0.29871}],"risk":0.28500000000000003,"urls":["https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g","https://nvd.nist.gov/vuln/detail/CVE-2026-84394","https://github.com/fastify/fast-uri/pull/214","https://github.com/fastify/fast-uri/commit/e00815236bc94107e44ef1b2f5318a06bac225c0","https://cna.openjsf.org/security-advisories.html","https://github.com/fastify/fast-uri/releases/tag/v2.4.6","https://github.com/fastify/fast-uri/releases/tag/v3.1.7","https://github.com/fastify/fast-uri/releases/tag/v4.1.4"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-58mr-gqgx-xq4g","description":"fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority"},"relatedVulnerabilities":[{"id":"CVE-2026-84394","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84394","cwe":"CWE-436","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-84394","date":"2026-10-08","epss":0.0038,"percentile":0.29871}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84394","description":"fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicalized as a domain name, so parse() returns it as the host with error undefined, while Node's URL and the HTTP clients built on it resolve the same string to a different host. An application that reads the parsed host to make a host decision, such as an SSRF denylist, a redirect allowlist, or proxy routing, and then passes the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches. The same host is carried through normalize, equal, and resolve. This affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, and is fixed in 2.4.6, 3.1.7, and 4.1.4, where parse() reports a malformed host for any host that contains a bracket but is not a valid IPv6 literal."}]},{"artifact":{"id":"759d8a1cdfa5f282","cpes":["cpe:2.3:a:simple-git_project:simple-git:3.36.0:*:*:*:*:node.js:*:*"],"name":"simple-git","purl":"pkg:npm/simple-git@3.36.0","type":"npm","version":"3.36.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/simple-git@3.36.0_supports-color@8.1.1/node_modules/simple-git/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/simple-git@3.36.0_supports-color@8.1.1/node_modules/simple-git/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-858h-whjf-mvg5","versionConstraint":"<=3.36.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"simple-git","version":"3.36.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-858h-whjf-mvg5","fix":{"state":"fixed","versions":["4.0.0"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"4.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102827","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102827","cwe":"CWE-88","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102827","date":"2026-10-08","epss":0.00363,"percentile":0.28066}],"risk":0.28314,"urls":["https://github.com/steveukx/git-js/security/advisories/GHSA-858h-whjf-mvg5","https://nvd.nist.gov/vuln/detail/CVE-2026-102827","https://github.com/steveukx/git-js/pull/1193","https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-858h-whjf-mvg5","description":"simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)"},"relatedVulnerabilities":[{"id":"CVE-2026-102827","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102827","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102827","cwe":"CWE-88","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102827","date":"2026-10-08","epss":0.00363,"percentile":0.28066}],"urls":["https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7","https://github.com/steveukx/git-js/pull/1193","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.0","https://github.com/steveukx/git-js/security/advisories/GHSA-858h-whjf-mvg5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102827","description":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --exec forms can therefore bypass detectVulnerableFlags, reach git push against a local or file remote or an attacker-influenced receive-pack target, and cause Git to invoke an attacker-selected command in consumers that expose those arguments. The clone-side abbreviation handling does not protect the push path. This issue is fixed in 4.0.0."}]},{"artifact":{"id":"5a0f4c103779f950","cpes":["cpe:2.3:a:zlib:zlib:1.3.2-r0:*:*:*:*:*:*:*"],"name":"zlib","purl":"pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"1.3.2-r0","language":"","licenses":["Zlib"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libz.so.1"},{"path":"/usr/lib/libz.so.1.3.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"zlib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"fixed","versions":["1.3.2-r1"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.3.2-r1"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x97p-jq2g-jp4f","versionConstraint":">=1.15.1,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-x97p-jq2g-jp4f","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101909","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101909","date":"2026-10-08","epss":0.00354,"percentile":0.27045}],"risk":0.27966,"urls":["https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f","https://nvd.nist.gov/vuln/detail/CVE-2026-101909","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b","https://github.com/axios/axios/releases/tag/v0.34.0","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x97p-jq2g-jp4f","description":"Axios: Prototype Pollution Gadget in axios toFormData Options"},"relatedVulnerabilities":[{"id":"CVE-2026-101909","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101909","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101909","date":"2026-10-08","epss":0.00354,"percentile":0.27045}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v0.34.0","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101909","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x97p-jq2g-jp4f","versionConstraint":">=1.15.1,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-x97p-jq2g-jp4f","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101909","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101909","date":"2026-10-08","epss":0.00354,"percentile":0.27045}],"risk":0.27966,"urls":["https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f","https://nvd.nist.gov/vuln/detail/CVE-2026-101909","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b","https://github.com/axios/axios/releases/tag/v0.34.0","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x97p-jq2g-jp4f","description":"Axios: Prototype Pollution Gadget in axios toFormData Options"},"relatedVulnerabilities":[{"id":"CVE-2026-101909","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101909","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101909","date":"2026-10-08","epss":0.00354,"percentile":0.27045}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v0.34.0","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101909","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0."}]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-80230"},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60002"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60002"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60002"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60002"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60002"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60002"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60002"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"9361a461f1bc8b3d","cpes":["cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.47-r0:*:*:*:*:*:*:*"],"name":"graphicsmagick","purl":"pkg:apk/alpine/graphicsmagick@1.3.47-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"1.3.47-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gm"},{"path":"/usr/lib"},{"path":"/usr/lib/libGraphicsMagick.la"},{"path":"/usr/lib/libGraphicsMagick.so.3"},{"path":"/usr/lib/libGraphicsMagick.so.3.27.0"},{"path":"/usr/lib/libGraphicsMagickWand.la"},{"path":"/usr/lib/libGraphicsMagickWand.so.2"},{"path":"/usr/lib/libGraphicsMagickWand.so.2.11.0"},{"path":"/usr/lib/GraphicsMagick-1.3.47"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/delegates.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type-ghostscript.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type-solaris.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type-urw-base35-otf.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type-windows.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/config/type.mgk"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/aai.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/aai.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/art.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/art.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/avs.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/avs.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/bmp.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/bmp.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/braille.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/braille.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cals.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cals.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/caption.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/caption.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cineon.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cineon.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cmyk.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cmyk.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cut.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/cut.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dcm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dcm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dcraw.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dcraw.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dib.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dib.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dpx.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/dpx.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ept.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ept.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/fax.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/fax.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/fits.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/fits.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gif.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gif.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gradient.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gradient.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gray.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/gray.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/heif.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/heif.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/histogram.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/histogram.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/hrz.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/hrz.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/html.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/html.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/icon.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/icon.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/identity.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/identity.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/info.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/info.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/jnx.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/jnx.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/jpeg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/jpeg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/label.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/label.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/locale.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/locale.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/logo.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/logo.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mac.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mac.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/map.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/map.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mat.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mat.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/matte.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/matte.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/meta.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/meta.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/miff.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/miff.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mono.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mono.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpc.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpc.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpeg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpeg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpr.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mpr.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/msl.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/msl.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mtv.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mtv.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mvg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/mvg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/null.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/null.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/otb.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/otb.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/palm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/palm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcd.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcd.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcl.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcl.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcx.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pcx.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pdb.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pdb.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pdf.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pdf.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pict.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pict.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pix.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pix.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/plasma.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/plasma.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/png.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/png.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pnm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pnm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/preview.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/preview.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps2.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps2.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps3.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ps3.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pwp.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/pwp.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rgb.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rgb.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rla.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rla.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rle.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/rle.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sct.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sct.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sfw.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sfw.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sgi.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sgi.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/stegano.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/stegano.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sun.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/sun.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/svg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/svg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tga.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tga.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tiff.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tiff.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tile.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tile.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tim.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/tim.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/topol.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/topol.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ttf.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/ttf.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/txt.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/txt.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/uil.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/uil.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/url.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/url.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/uyvy.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/uyvy.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/vicar.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/vicar.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/vid.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/vid.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/viff.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/viff.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wbmp.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wbmp.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/webp.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/webp.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wmf.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wmf.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wpg.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/wpg.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xbm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xbm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xc.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xc.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xcf.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xcf.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xpm.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/xpm.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/yuv.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/coders/yuv.so"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/filters"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/filters/analyze.la"},{"path":"/usr/lib/GraphicsMagick-1.3.47/modules-Q16/filters/analyze.so"},{"path":"/usr/share"},{"path":"/usr/share/GraphicsMagick-1.3.47"},{"path":"/usr/share/GraphicsMagick-1.3.47/config"},{"path":"/usr/share/GraphicsMagick-1.3.47/config/colors.mgk"},{"path":"/usr/share/GraphicsMagick-1.3.47/config/log.mgk"},{"path":"/usr/share/GraphicsMagick-1.3.47/config/modules.mgk"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"graphicsmagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-32460","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.47:*:*:*:*:*:*:*"],"package":{"name":"graphicsmagick","version":"1.3.47-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-32460","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32460","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-32460","date":"2026-10-08","epss":0.00353,"percentile":0.26953}],"risk":0.2744575,"urls":["https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/8e56520435df50f618a03f2721a39a70a515f1cb","https://issues.oss-fuzz.com/issues/406320404","https://tracker.debian.org/news/1636753/accepted-graphicsmagick-14really1345hg17696-1-source-into-unstable/"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-32460","description":"GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call."},"relatedVulnerabilities":[]},{"artifact":{"id":"cfdc4678d94e94f6","cpes":["cpe:2.3:a:multer:multer:2.3.0:*:*:*:*:*:*:*"],"name":"multer","purl":"pkg:npm/multer@2.3.0","type":"npm","version":"2.3.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/multer@2.3.0/node_modules/multer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/multer@2.3.0/node_modules/multer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pph-fpjx-jg34","versionConstraint":">=2.2.0,<2.4.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"multer","version":"2.3.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3pph-fpjx-jg34","fix":{"state":"fixed","versions":["2.4.0"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.4.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88932","cwe":"CWE-400","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-88932","cwe":"CWE-459","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-88932","date":"2026-10-08","epss":0.00532,"percentile":0.43154}],"risk":0.27398,"urls":["https://github.com/expressjs/multer/security/advisories/GHSA-3pph-fpjx-jg34","https://nvd.nist.gov/vuln/detail/CVE-2026-88932","https://github.com/expressjs/multer/commit/53337f9713619ef3381ee6b4e541f926dbaac305","https://cna.openjsf.org/security-advisories.html","https://github.com/expressjs/multer/releases/tag/v2.4.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pph-fpjx-jg34","description":"multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads"},"relatedVulnerabilities":[{"id":"CVE-2026-88932","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88932","cwe":"CWE-400","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-88932","cwe":"CWE-459","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-88932","date":"2026-10-08","epss":0.00532,"percentile":0.43154}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/expressjs/multer/security/advisories/GHSA-3pph-fpjx-jg34"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88932","description":"multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later."}]},{"artifact":{"id":"f177012132788aa6","cpes":["cpe:2.3:a:hono:hono:4.12.34:*:*:*:*:node.js:*:*"],"name":"hono","purl":"pkg:npm/hono@4.12.34","type":"npm","version":"4.12.34","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/hono@4.12.34/node_modules/hono/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/hono@4.12.34/node_modules/hono/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.13.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g6gw-c38x-mqfc","versionConstraint":"<4.13.5 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"hono","version":"4.12.34"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-g6gw-c38x-mqfc","fix":{"state":"fixed","versions":["4.13.5"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.13.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84364","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84364","date":"2026-10-08","epss":0.00529,"percentile":0.42961}],"risk":0.27243500000000004,"urls":["https://github.com/honojs/hono/security/advisories/GHSA-g6gw-c38x-mqfc","https://nvd.nist.gov/vuln/detail/CVE-2026-84364","https://github.com/honojs/hono/commit/531e9c5a3ae058d10de33f643055bd4009a87178","https://github.com/honojs/hono/releases/tag/v4.13.5"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g6gw-c38x-mqfc","description":"Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-84364","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84364","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84364","date":"2026-10-08","epss":0.00529,"percentile":0.42961}],"urls":["https://github.com/honojs/hono/commit/531e9c5a3ae058d10de33f643055bd4009a87178","https://github.com/honojs/hono/releases/tag/v4.13.5","https://github.com/honojs/hono/security/advisories/GHSA-g6gw-c38x-mqfc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84364","description":"Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested objects with dot-notation parsing enabled, it does not limit the nesting depth or the total number of intermediate objects created. Empty segments are preserved, so one deeply dotted field name can encode one nesting level per byte, while a large number of shallowly dotted fields can create the same amplification across a request. A request body within a normal size limit can therefore allocate an object graph far larger than the request after the body has already been accepted. An unauthenticated attacker who can reach an affected endpoint can send concurrent requests that exhaust the JavaScript heap, terminate the server process, and leave the service unavailable until restart. Dot-notation parsing is not enabled by default, and applications using the default behavior are not affected. This issue is fixed in version 4.13.5."}]},{"artifact":{"id":"fde10c1d4bbab706","cpes":["cpe:2.3:a:qs_project:qs:6.15.2:*:*:*:*:node.js:*:*"],"name":"qs","purl":"pkg:npm/qs@6.15.2","type":"npm","version":"6.15.2","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/qs@6.15.2/node_modules/qs/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/qs@6.15.2/node_modules/qs/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.16.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5fp-wj9c-mxmx","versionConstraint":">=6.14.2,<=6.15.3 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"qs","version":"6.15.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-x5fp-wj9c-mxmx","fix":{"state":"fixed","versions":["6.16.0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"6.16.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82562","cwe":"CWE-770","type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"}],"epss":[{"cve":"CVE-2026-82562","date":"2026-10-08","epss":0.0054,"percentile":0.4367}],"risk":0.27,"urls":["https://github.com/ljharb/qs/security/advisories/GHSA-w7fw-mjwx-w883","https://github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx","https://nvd.nist.gov/vuln/detail/CVE-2026-82562","https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5fp-wj9c-mxmx","description":"qs array-limit bypass via bracket-key comma parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-82562","cvss":[{"type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82562","cwe":"CWE-770","type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"}],"epss":[{"cve":"CVE-2026-82562","date":"2026-10-08","epss":0.0054,"percentile":0.4367}],"urls":["https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464","https://github.com/ljharb/qs/security/advisories/GHSA-w7fw-mjwx-w883","https://github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82562","description":"### Summary\n\n\n\nWhen `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`), an indexed key (`a[0]=`), a nested key (`a[b]=`), or a dotted key (`a.b=` with `allowDots`) throws the documented `RangeError`. A single parameter such as `a[]=1,2,2,...` therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the `[]=` key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover.\n\n\n\n### Details\n\n\n\nIn `lib/parse.js`, a comma-separated value under a `[]=` key is split and then wrapped as a single nested element (`val = [val]`, so that each `a[]=x,y` group counts as one element of the outer array). The `arrayLimit` check that 6.14.2 added for comma values runs after that wrap, so for `[]=` parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an `isFlatArrayValue` flag that `parseValues` set to `false` for any part containing `[]=`, and did not pass it for object-valued input, so the gap remained.\n\n\n\n#### PoC\n\n\n\n```js\n\n\n\nvar qs = require('qs');\n\n\n\nvar options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true };\n\n\n\nqs.parse('a=1,2,3,4', options);   // RangeError: Array limit exceeded. Only 3 elements allowed in an array.\n\n\n\nqs.parse('a[]=1,2,3,4', options); // { a: [ [ '1', '2', '3', '4' ] ] }  (no throw)\n\n\n\nqs.parse('a[]=' + '1,'.repeat(1000000) + '1', { comma: true, arrayLimit: 20, throwOnLimitExceeded: true });\n\n\n\n// no throw; a 1,000,001-element inner array is allocated\n\n\n\n```\n\n\n\n#### Fix\n\n\n\n`lib/parse.js`, applied in 8859c37 on `main` and released as v6.16.0: the `isFlatArrayValue` gate is removed, so every comma-split value is counted against `arrayLimit` before splitting regardless of key form. An in-limit group under `a[]=` still counts as one element of the outer array, and the default (`throwOnLimitExceeded: false`) path is unchanged.\n\n\n\n### Affected versions\n\n\n\n`>=6.14.2 <6.16.0`, fixed in v6.16.0.\n\n\n\nv6.14.2 introduced `arrayLimit` enforcement for comma values (the fix for CVE-2026-2391) but only for values not under a `[]=` key, and every release from v6.14.2 through v6.15.3 has the same gap. v6.14.0 and v6.14.1, where `throwOnLimitExceeded` exists but does not apply to any comma form, are covered by CVE-2026-2391 rather than this record. Earlier lines (6.7.x through 6.13.x) have `comma` but no `throwOnLimitExceeded`, so there is no hard cap on any comma path to bypass; releases before 6.7.0 have no `comma` option.\n\n\n\n### Impact\n\n\n\nAn unauthenticated attacker who can reach an application that parses untrusted query strings or urlencoded bodies with both `comma: true` and `throwOnLimitExceeded: true` (both non-default) can bypass the configured limit with a single `a[]=` parameter and force the parser to allocate an array proportional to the request size. The cost is strictly linear in the attacker-supplied bytes (about 0.1 microseconds and 6 to 7 retained bytes per input byte; the same out-of-memory threshold as the documented default `throwOnLimitExceeded: false` path), so a transport-layer request or body size limit bounds it completely (and node's default maximum HTTP header size of 16 KB already bounds the request line, so multi-megabyte payloads need a body parser). The impact is that an opt-in hard limit fails open on one key spelling, not unbounded allocation from a small input."}]},{"artifact":{"id":"416a9506ffa9ec40","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.1.4:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.1.4","type":"npm","version":"2.1.4","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@2.1.4/node_modules/brace-expansion/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@2.1.4/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6j4f-fj2g-mc7p","versionConstraint":">=2.0.0,<2.1.5 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.1.4"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6j4f-fj2g-mc7p","fix":{"state":"fixed","versions":["2.1.5"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.1.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p","https://nvd.nist.gov/vuln/detail/CVE-2026-102276","https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6j4f-fj2g-mc7p","description":"brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102276","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102276","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10."}]},{"artifact":{"id":"416a9506ffa9ec40","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.1.4:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.1.4","type":"npm","version":"2.1.4","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@2.1.4/node_modules/brace-expansion/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@2.1.4/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qhr7-859c-m2p7","versionConstraint":">=2.0.0,<2.1.6 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.1.4"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-qhr7-859c-m2p7","fix":{"state":"fixed","versions":["2.1.6"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.1.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7","https://nvd.nist.gov/vuln/detail/CVE-2026-102278","https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qhr7-859c-m2p7","description":"brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102278","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102278","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11."}]},{"artifact":{"id":"9b333847e4cf6c68","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.7:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.7","type":"npm","version":"5.0.7","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6j4f-fj2g-mc7p","versionConstraint":">=4.0.0,<5.0.10 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.7"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6j4f-fj2g-mc7p","fix":{"state":"fixed","versions":["5.0.10"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p","https://nvd.nist.gov/vuln/detail/CVE-2026-102276","https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6j4f-fj2g-mc7p","description":"brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102276","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102276","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10."}]},{"artifact":{"id":"9b333847e4cf6c68","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.7:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.7","type":"npm","version":"5.0.7","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qhr7-859c-m2p7","versionConstraint":">=4.0.0,<5.0.11 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.7"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-qhr7-859c-m2p7","fix":{"state":"fixed","versions":["5.0.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7","https://nvd.nist.gov/vuln/detail/CVE-2026-102278","https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qhr7-859c-m2p7","description":"brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102278","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102278","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11."}]},{"artifact":{"id":"4ab07d6591eefe2f","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@5.0.9/node_modules/brace-expansion/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@5.0.9/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6j4f-fj2g-mc7p","versionConstraint":">=4.0.0,<5.0.10 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6j4f-fj2g-mc7p","fix":{"state":"fixed","versions":["5.0.10"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p","https://nvd.nist.gov/vuln/detail/CVE-2026-102276","https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6j4f-fj2g-mc7p","description":"brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102276","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102276","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10."}]},{"artifact":{"id":"10dadf83fd0e284c","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6j4f-fj2g-mc7p","versionConstraint":">=4.0.0,<5.0.10 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6j4f-fj2g-mc7p","fix":{"state":"fixed","versions":["5.0.10"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p","https://nvd.nist.gov/vuln/detail/CVE-2026-102276","https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6j4f-fj2g-mc7p","description":"brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102276","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102276","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10."}]},{"artifact":{"id":"10dadf83fd0e284c","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qhr7-859c-m2p7","versionConstraint":">=4.0.0,<5.0.11 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-qhr7-859c-m2p7","fix":{"state":"fixed","versions":["5.0.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7","https://nvd.nist.gov/vuln/detail/CVE-2026-102278","https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qhr7-859c-m2p7","description":"brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102278","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102278","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11."}]},{"artifact":{"id":"4ab07d6591eefe2f","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@5.0.9/node_modules/brace-expansion/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@5.0.9/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qhr7-859c-m2p7","versionConstraint":">=4.0.0,<5.0.11 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-qhr7-859c-m2p7","fix":{"state":"fixed","versions":["5.0.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7","https://nvd.nist.gov/vuln/detail/CVE-2026-102278","https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qhr7-859c-m2p7","description":"brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102278","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102278","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11."}]},{"artifact":{"id":"5e2ab97b23f852fa","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.2.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.2.0","type":"npm","version":"10.2.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.2.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-22jq-vg5j-6vgg","versionConstraint":">=10.1.1,<=10.2.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-22jq-vg5j-6vgg","fix":{"state":"fixed","versions":["10.2.1"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"10.2.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54272","cwe":"CWE-20","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54272","cwe":"CWE-918","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54272","date":"2026-10-08","epss":0.0043,"percentile":0.35247}],"risk":0.25585,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg","https://nvd.nist.gov/vuln/detail/CVE-2026-54272","https://github.com/beaugunderson/ip-address/commit/4a1f613f4c1bec915677dea923c10aaa09361ef9","https://github.com/beaugunderson/ip-address/releases/tag/v10.2.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-22jq-vg5j-6vgg","description":"ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks"},"relatedVulnerabilities":[{"id":"CVE-2026-54272","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54272","cwe":"CWE-20","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54272","cwe":"CWE-918","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54272","date":"2026-10-08","epss":0.0043,"percentile":0.35247}],"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54272","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. That table had no entry for the IPv4-mapped range (::ffff:0:0/96), so every mapped address fell through to Global unicast; NAT64 addresses matched their own NAT64 … labels. The boolean checks isLoopback, isUnspecified, and isMulticast compared getType() against a fixed label and so returned false, while isLinkLocal and isULA checked only the native IPv6 ranges. The library already exposed isMapped4() and to4(), but did not apply them inside these checks, so a mapped or NAT64 address was never normalized to its embedded IPv4 address before classification. For IPv4-mapped addresses the host OS routes to the IPv4 stack, so the misclassification is reachable on any dual-stack host. For NAT64, the classification bypass is unconditional but end-to-end reachability additionally requires a NAT64/DNS64 gateway in the deployment network.This issue has been fixed in version 10.2.1."}]},{"artifact":{"id":"631511184b49ac5d","cpes":["cpe:2.3:a:nodemailer:nodemailer:8.0.10:*:*:*:*:node.js:*:*"],"name":"nodemailer","purl":"pkg:npm/nodemailer@8.0.10","type":"npm","version":"8.0.10","language":"javascript","licenses":["MIT-0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"9.0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6gq-j5cr-w38f","versionConstraint":"<=9.0.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"nodemailer","version":"8.0.10"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-p6gq-j5cr-w38f","fix":{"state":"fixed","versions":["9.0.1"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"9.0.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82659","cwe":"CWE-73","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-82659","date":"2026-10-08","epss":0.00349,"percentile":0.26371}],"risk":0.25477,"urls":["https://github.com/nodemailer/nodemailer/security/advisories/GHSA-p6gq-j5cr-w38f","https://github.com/Sif-0x01/security-advisories/security/advisories/GHSA-68x8-4h5v-r533","https://nvd.nist.gov/vuln/detail/CVE-2026-82659","https://github.com/nodemailer/nodemailer/commit/a82e060d978f27e5f41369a9a9807b1e3dedc2e2","https://github.com/nodemailer/nodemailer/releases/tag/v9.0.1","https://www.vulncheck.com/advisories/nodemailer-before-9.0.1-file-read-and-ssrf-via-raw-option"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6gq-j5cr-w38f","description":"Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message"},"relatedVulnerabilities":[{"id":"CVE-2026-82659","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82659","cwe":"CWE-73","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-82659","date":"2026-10-08","epss":0.00349,"percentile":0.26371}],"urls":["https://github.com/nodemailer/nodemailer/security/advisories/GHSA-p6gq-j5cr-w38f","https://www.vulncheck.com/advisories/nodemailer-before-9.0.1-file-read-and-ssrf-via-raw-option"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82659","description":"nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j8rh-479h-cp32","versionConstraint":">=1.0.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j8rh-479h-cp32","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101904","cwe":"CWE-74","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101904","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101904","date":"2026-10-08","epss":0.00428,"percentile":0.35075}],"risk":0.25466,"urls":["https://github.com/axios/axios/security/advisories/GHSA-j8rh-479h-cp32","https://nvd.nist.gov/vuln/detail/CVE-2026-101904","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j8rh-479h-cp32","description":"Axios: Header Injection via Inherited headers After Minimal Interceptor"},"relatedVulnerabilities":[{"id":"CVE-2026-101904","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101904","cwe":"CWE-74","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101904","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101904","date":"2026-10-08","epss":0.00428,"percentile":0.35075}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-j8rh-479h-cp32"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101904","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollution flaw sets Object.prototype.headers, and trusted request interceptors return a new ordinary configuration without an own headers property. After the interceptor chain, dispatchRequest resolves the inherited headers during normalization. Downstream request processing can observe attacker-controlled headers, including authorization-related values. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j8rh-479h-cp32","versionConstraint":">=1.0.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j8rh-479h-cp32","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101904","cwe":"CWE-74","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101904","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101904","date":"2026-10-08","epss":0.00428,"percentile":0.35075}],"risk":0.25466,"urls":["https://github.com/axios/axios/security/advisories/GHSA-j8rh-479h-cp32","https://nvd.nist.gov/vuln/detail/CVE-2026-101904","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j8rh-479h-cp32","description":"Axios: Header Injection via Inherited headers After Minimal Interceptor"},"relatedVulnerabilities":[{"id":"CVE-2026-101904","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101904","cwe":"CWE-74","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101904","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101904","date":"2026-10-08","epss":0.00428,"percentile":0.35075}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-j8rh-479h-cp32"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101904","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollution flaw sets Object.prototype.headers, and trusted request interceptors return a new ordinary configuration without an own headers property. After the interceptor chain, dispatchRequest resolves the inherited headers during normalization. Downstream request processing can observe attacker-controlled headers, including authorization-related values. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"9efa366ab366f908","cpes":["cpe:2.3:a:\\@langchain\\/mongodb:\\@langchain\\/mongodb:1.0.1:*:*:*:*:*:*:*","cpe:2.3:a:langchain-ai:\\@langchain\\/mongodb:1.0.1:*:*:*:*:*:*:*"],"name":"@langchain/mongodb","purl":"pkg:npm/%40langchain/mongodb@1.0.1","type":"npm","version":"1.0.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@langchain+mongodb@1.0.1_@aws-sdk+credential-providers@3.808.0_@langchain+core@1.2.8_@o_b0bbf785bb992216d041cc6a270728fb/node_modules/@langchain/mongodb/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@langchain+mongodb@1.0.1_@aws-sdk+credential-providers@3.808.0_@langchain+core@1.2.8_@o_b0bbf785bb992216d041cc6a270728fb/node_modules/@langchain/mongodb/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.3.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m6rx-h84q-8r95","versionConstraint":"<=1.3.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@langchain/mongodb","version":"1.0.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-m6rx-h84q-8r95","fix":{"state":"fixed","versions":["1.3.1"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1.3.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106119","cwe":"CWE-943","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106119","date":"2026-10-08","epss":0.00463,"percentile":0.38127}],"risk":0.25465000000000004,"urls":["https://github.com/langchain-ai/langchainjs/security/advisories/GHSA-m6rx-h84q-8r95","https://nvd.nist.gov/vuln/detail/CVE-2026-106119","https://github.com/langchain-ai/langchainjs/pull/11672","https://github.com/langchain-ai/langchainjs/commit/946e3d856ff1f8ce7f7b9374c83f680a6ada79af","https://github.com/langchain-ai/langchainjs/releases/tag/@langchain/mongodb@1.3.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m6rx-h84q-8r95","description":"LangChain: MongoDBChatMessageHistory query injection can allow cross-session access"},"relatedVulnerabilities":[{"id":"CVE-2026-106119","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106119","cwe":"CWE-943","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106119","date":"2026-10-08","epss":0.00463,"percentile":0.38127}],"urls":["https://github.com/langchain-ai/langchainjs/commit/946e3d856ff1f8ce7f7b9374c83f680a6ada79af","https://github.com/langchain-ai/langchainjs/pull/11672","https://github.com/langchain-ai/langchainjs/releases/tag/@langchain/mongodb@1.3.1","https://github.com/langchain-ai/langchainjs/security/advisories/GHSA-m6rx-h84q-8r95"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106119","description":"LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime, allowing the identifier to be interpreted as a MongoDB query condition rather than as a literal value when multiple users' histories are stored in a shared MongoDB collection. An attacker able to invoke chat-history operations can read, modify, or delete another user's stored conversation. Applications using authenticated, server-controlled string identifiers are not affected. This issue is fixed in version 1.3.1."}]},{"artifact":{"id":"f177012132788aa6","cpes":["cpe:2.3:a:hono:hono:4.12.34:*:*:*:*:node.js:*:*"],"name":"hono","purl":"pkg:npm/hono@4.12.34","type":"npm","version":"4.12.34","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/hono@4.12.34/node_modules/hono/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/hono@4.12.34/node_modules/hono/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.13.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gqvv-2mrq-wpjv","versionConstraint":"<4.13.5 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"hono","version":"4.12.34"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-gqvv-2mrq-wpjv","fix":{"state":"fixed","versions":["4.13.5"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.13.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84365","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84365","date":"2026-10-08","epss":0.00437,"percentile":0.36007}],"risk":0.25127499999999997,"urls":["https://github.com/honojs/hono/security/advisories/GHSA-gqvv-2mrq-wpjv","https://nvd.nist.gov/vuln/detail/CVE-2026-84365","https://github.com/honojs/hono/commit/3a67f7f3997e1437d108f7bcba2dbcee2df69221","https://github.com/honojs/hono/releases/tag/v4.13.5"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gqvv-2mrq-wpjv","description":"Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory"},"relatedVulnerabilities":[{"id":"CVE-2026-84365","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84365","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84365","date":"2026-10-08","epss":0.00437,"percentile":0.36007}],"urls":["https://github.com/honojs/hono/commit/3a67f7f3997e1437d108f7bcba2dbcee2df69221","https://github.com/honojs/hono/releases/tag/v4.13.5","https://github.com/honojs/hono/security/advisories/GHSA-gqvv-2mrq-wpjv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84365","description":"Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG() can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments. Static site generation builds each output path from the route path and values supplied through ssgParams, then verifies that the result stays inside the output directory using the same normalization routine that built the path. That routine does not fully collapse runs of consecutive parent-directory segments, allowing a path that the check accepts to resolve outside the output directory, and the check also treats output directories that differ in how they are rooted as equivalent. This arises when an application generates a static site from route parameter values it does not fully control, such as slugs from a CMS, API, or user submission. An untrusted ssgParams value can create or overwrite files elsewhere in the build environment and alter generated artifacts or deployment output. The vulnerability affects build-time static site generation only; request-time routing and applications with entirely developer-controlled ssgParams values are not affected. This issue is fixed in version 4.13.5."}]},{"artifact":{"id":"90b2fe63ad4df1bf","cpes":["cpe:2.3:a:\\@simple-git\\/argv-parser:\\@simple-git\\/argv-parser:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:\\@simple-git\\/argv-parser:\\@simple_git\\/argv_parser:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:\\@simple_git\\/argv_parser:\\@simple-git\\/argv-parser:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:\\@simple_git\\/argv_parser:\\@simple_git\\/argv_parser:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:\\@simple-git\\/argv:\\@simple-git\\/argv-parser:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:\\@simple-git\\/argv:\\@simple_git\\/argv_parser:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:\\@simple_git\\/argv:\\@simple-git\\/argv-parser:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:\\@simple_git\\/argv:\\@simple_git\\/argv_parser:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:\\@simple:\\@simple-git\\/argv-parser:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:\\@simple:\\@simple_git\\/argv_parser:1.1.1:*:*:*:*:*:*:*"],"name":"@simple-git/argv-parser","purl":"pkg:npm/%40simple-git/argv-parser@1.1.1","type":"npm","version":"1.1.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@simple-git+argv-parser@1.1.1/node_modules/@simple-git/argv-parser/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@simple-git+argv-parser@1.1.1/node_modules/@simple-git/argv-parser/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v5rq-49vh-5v5c","versionConstraint":"<2.0.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@simple-git/argv-parser","version":"1.1.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-v5rq-49vh-5v5c","fix":{"state":"fixed","versions":["2.0.1"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"2.0.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102829","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102829","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102829","date":"2026-10-08","epss":0.00275,"percentile":0.18237}],"risk":0.25025,"urls":["https://github.com/steveukx/git-js/security/advisories/GHSA-v5rq-49vh-5v5c","https://nvd.nist.gov/vuln/detail/CVE-2026-102829","https://github.com/steveukx/git-js/pull/1201","https://github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4","https://github.com/steveukx/git-js/releases/tag/@simple-git/argv-parser@2.0.1"],"severity":"Critical","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v5rq-49vh-5v5c","description":"simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection"},"relatedVulnerabilities":[{"id":"CVE-2026-102829","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102829","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102829","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102829","date":"2026-10-08","epss":0.00275,"percentile":0.18237}],"urls":["https://github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4","https://github.com/steveukx/git-js/pull/1201","https://github.com/steveukx/git-js/releases/tag/@simple-git/argv-parser@2.0.1","https://github.com/steveukx/git-js/security/advisories/GHSA-v5rq-49vh-5v5c"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102829","description":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A consuming application that forwards attacker-influenced environment values can therefore allow Git to invoke an attacker-selected editor during operations such as commit amendment or interactive rebase when no higher-priority editor setting overrides VISUAL and Git's terminal prerequisites are met. The executable runs with the privileges of the Node.js process. This issue is fixed in argv-parser 2.0.1."}]},{"artifact":{"id":"759d8a1cdfa5f282","cpes":["cpe:2.3:a:simple-git_project:simple-git:3.36.0:*:*:*:*:node.js:*:*"],"name":"simple-git","purl":"pkg:npm/simple-git@3.36.0","type":"npm","version":"3.36.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/simple-git@3.36.0_supports-color@8.1.1/node_modules/simple-git/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/simple-git@3.36.0_supports-color@8.1.1/node_modules/simple-git/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x6jw-m9v5-85vh","versionConstraint":">=3.15.0,<4.0.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"simple-git","version":"3.36.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-x6jw-m9v5-85vh","fix":{"state":"fixed","versions":["4.0.1"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"4.0.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102828","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102828","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102828","date":"2026-10-08","epss":0.00275,"percentile":0.18237}],"risk":0.25025,"urls":["https://github.com/steveukx/git-js/security/advisories/GHSA-x6jw-m9v5-85vh","https://nvd.nist.gov/vuln/detail/CVE-2026-102828","https://github.com/steveukx/git-js/pull/1198","https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.1"],"severity":"Critical","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x6jw-m9v5-85vh","description":"simple-git unsafe-operation guard does not block trailer command configuration"},"relatedVulnerabilities":[{"id":"CVE-2026-102828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102828","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102828","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102828","date":"2026-10-08","epss":0.00275,"percentile":0.18237}],"urls":["https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3","https://github.com/steveukx/git-js/pull/1198","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.1","https://github.com/steveukx/git-js/security/advisories/GHSA-x6jw-m9v5-85vh"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102828","description":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9fr6-4gfg-395g","versionConstraint":">=1.0.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-9fr6-4gfg-395g","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101902","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101902","date":"2026-10-08","epss":0.00413,"percentile":0.33524}],"risk":0.245735,"urls":["https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g","https://nvd.nist.gov/vuln/detail/CVE-2026-101902","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v0.34.0","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9fr6-4gfg-395g","description":"Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method"},"relatedVulnerabilities":[{"id":"CVE-2026-101902","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101902","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101902","date":"2026-10-08","epss":0.00413,"percentile":0.33524}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v0.34.0","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101902","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9fr6-4gfg-395g","versionConstraint":">=1.0.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-9fr6-4gfg-395g","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101902","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101902","date":"2026-10-08","epss":0.00413,"percentile":0.33524}],"risk":0.245735,"urls":["https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g","https://nvd.nist.gov/vuln/detail/CVE-2026-101902","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v0.34.0","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9fr6-4gfg-395g","description":"Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method"},"relatedVulnerabilities":[{"id":"CVE-2026-101902","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101902","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101902","date":"2026-10-08","epss":0.00413,"percentile":0.33524}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v0.34.0","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101902","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vh66-26gq-q6x8","versionConstraint":">=1.7.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-vh66-26gq-q6x8","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101908","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101908","date":"2026-10-08","epss":0.00413,"percentile":0.33524}],"risk":0.245735,"urls":["https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8","https://nvd.nist.gov/vuln/detail/CVE-2026-101908","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vh66-26gq-q6x8","description":"Axios: Prototype pollution gadget in fetch adapter can alter outbound requests"},"relatedVulnerabilities":[{"id":"CVE-2026-101908","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101908","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101908","date":"2026-10-08","epss":0.00413,"percentile":0.33524}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101908","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. Attacker-controlled request headers can alter authorization, caching, metadata-service access, or application-specific behavior. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vh66-26gq-q6x8","versionConstraint":">=1.7.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-vh66-26gq-q6x8","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101908","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101908","date":"2026-10-08","epss":0.00413,"percentile":0.33524}],"risk":0.245735,"urls":["https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8","https://nvd.nist.gov/vuln/detail/CVE-2026-101908","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vh66-26gq-q6x8","description":"Axios: Prototype pollution gadget in fetch adapter can alter outbound requests"},"relatedVulnerabilities":[{"id":"CVE-2026-101908","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101908","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101908","date":"2026-10-08","epss":0.00413,"percentile":0.33524}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101908","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. Attacker-controlled request headers can alter authorization, caching, metadata-service access, or application-specific behavior. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"f177012132788aa6","cpes":["cpe:2.3:a:hono:hono:4.12.34:*:*:*:*:node.js:*:*"],"name":"hono","purl":"pkg:npm/hono@4.12.34","type":"npm","version":"4.12.34","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/hono@4.12.34/node_modules/hono/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/hono@4.12.34/node_modules/hono/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.13.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-crvj-82cr-hjcx","versionConstraint":"<4.13.5 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"hono","version":"4.12.34"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-crvj-82cr-hjcx","fix":{"state":"fixed","versions":["4.13.5"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.13.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84363","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84363","date":"2026-10-08","epss":0.00448,"percentile":0.36951}],"risk":0.24416,"urls":["https://github.com/honojs/hono/security/advisories/GHSA-crvj-82cr-hjcx","https://nvd.nist.gov/vuln/detail/CVE-2026-84363","https://github.com/honojs/hono/commit/9c28d724c5a7fb086ebaa812fdc1ad6e957c63bc","https://github.com/honojs/hono/releases/tag/v4.13.5"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-crvj-82cr-hjcx","description":"Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials"},"relatedVulnerabilities":[{"id":"CVE-2026-84363","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84363","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84363","date":"2026-10-08","epss":0.00448,"percentile":0.36951}],"urls":["https://github.com/honojs/hono/commit/9c28d724c5a7fb086ebaa812fdc1ad6e957c63bc","https://github.com/honojs/hono/releases/tag/v4.13.5","https://github.com/honojs/hono/security/advisories/GHSA-crvj-82cr-hjcx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84363","description":"Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragment as the start of a query string, so the application can read request parameters that browsers, new URL(), reverse proxies, filtering rules, parameter allow and deny lists, access logging, request validation, and other middleware do not observe. The Cache Middleware removes the fragment when building its cache key, allowing a response influenced by parameters inside the fragment to be stored under a key that omits those parameters and later served to other users. This can bypass filtering and auditing, poison cached responses, and enable stored cross-site scripting when an affected parameter is reflected into cached HTML without escaping. Exploitation requires a runtime and intermediary path that passes a literal hash character through to the request URL; Cloudflare Workers and intermediaries that strip fragments are not affected. This issue is fixed in version 4.13.5."}]},{"artifact":{"id":"38ca7e9b9a10442b","cpes":["cpe:2.3:a:prosemirror-view:prosemirror-view:1.41.8:*:*:*:*:*:*:*","cpe:2.3:a:prosemirror-view:prosemirror_view:1.41.8:*:*:*:*:*:*:*","cpe:2.3:a:prosemirror_view:prosemirror-view:1.41.8:*:*:*:*:*:*:*","cpe:2.3:a:prosemirror_view:prosemirror_view:1.41.8:*:*:*:*:*:*:*","cpe:2.3:a:prosemirror:prosemirror-view:1.41.8:*:*:*:*:*:*:*","cpe:2.3:a:prosemirror:prosemirror_view:1.41.8:*:*:*:*:*:*:*"],"name":"prosemirror-view","purl":"pkg:npm/prosemirror-view@1.41.8","type":"npm","version":"1.41.8","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/prosemirror-view@1.41.8/node_modules/prosemirror-view/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/prosemirror-view@1.41.8/node_modules/prosemirror-view/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.42.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c8x8-7fp4-3x9w","versionConstraint":"<1.42.3 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"prosemirror-view","version":"1.41.8"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-c8x8-7fp4-3x9w","fix":{"state":"fixed","versions":["1.42.3"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.42.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104847","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104847","date":"2026-10-08","epss":0.00305,"percentile":0.21301}],"risk":0.24400000000000002,"urls":["https://github.com/ProseMirror/prosemirror-view/security/advisories/GHSA-c8x8-7fp4-3x9w","https://nvd.nist.gov/vuln/detail/CVE-2026-104847","https://github.com/ProseMirror/prosemirror-view/commit/20dc0a911a79f8fc6640dbbea5e7d68d3c4784b7","https://github.com/ProseMirror/prosemirror-view/commit/2e91a612bbc1248e55b4f6061fc93fe459f977c1"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c8x8-7fp4-3x9w","description":"ProseMirror has a XSS vulnerability in prosemirror-view's paste handling"},"relatedVulnerabilities":[{"id":"CVE-2026-104847","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104847","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104847","date":"2026-10-08","epss":0.00305,"percentile":0.21301}],"urls":["https://github.com/ProseMirror/prosemirror-view/commit/20dc0a911a79f8fc6640dbbea5e7d68d3c4784b7","https://github.com/ProseMirror/prosemirror-view/commit/2e91a612bbc1248e55b4f6061fc93fe459f977c1","https://github.com/ProseMirror/prosemirror-view/security/advisories/GHSA-c8x8-7fp4-3x9w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104847","description":"ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema attribute validation. When a user pastes the crafted HTML into an editor, the unvalidated context attributes can construct content that executes attacker-controlled JavaScript in the browser window containing the editor. This issue is fixed in version 1.42.3."}]},{"artifact":{"id":"5e2ab97b23f852fa","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.2.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.2.0","type":"npm","version":"10.2.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2vr4-cq9g-pvrc","versionConstraint":">=10.2.0,<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-2vr4-cq9g-pvrc","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-08","epss":0.00386,"percentile":0.3054}],"risk":0.22967,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc","https://nvd.nist.gov/vuln/detail/CVE-2026-101910","https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2vr4-cq9g-pvrc","description":"ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-101910","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-08","epss":0.00386,"percentile":0.3054}],"urls":["https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101910","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback, and isLinkLocal for a trust-boundary decision can treat an internal IPv4 destination encoded through that range as external. Exploitation depends on a server network using an operator-selected NAT64 prefix within the local-use range. A successful bypass can cross the intended network trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"ee4435d9da2328c8","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.3.1:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.3.1","type":"npm","version":"10.3.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2vr4-cq9g-pvrc","versionConstraint":">=10.2.0,<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.3.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-2vr4-cq9g-pvrc","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-08","epss":0.00386,"percentile":0.3054}],"risk":0.22967,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc","https://nvd.nist.gov/vuln/detail/CVE-2026-101910","https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2vr4-cq9g-pvrc","description":"ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-101910","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-08","epss":0.00386,"percentile":0.3054}],"urls":["https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101910","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback, and isLinkLocal for a trust-boundary decision can treat an internal IPv4 destination encoded through that range as external. Exploitation depends on a server network using an operator-selected NAT64 prefix within the local-use range. A successful bypass can cross the intended network trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"aa86ffe12b42801d","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.3.1:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.3.1","type":"npm","version":"10.3.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/ip-address@10.3.1/node_modules/ip-address/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/ip-address@10.3.1/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2vr4-cq9g-pvrc","versionConstraint":">=10.2.0,<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.3.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-2vr4-cq9g-pvrc","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-08","epss":0.00386,"percentile":0.3054}],"risk":0.22967,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc","https://nvd.nist.gov/vuln/detail/CVE-2026-101910","https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2vr4-cq9g-pvrc","description":"ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-101910","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-08","epss":0.00386,"percentile":0.3054}],"urls":["https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101910","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback, and isLinkLocal for a trust-boundary decision can treat an internal IPv4 destination encoded through that range as external. Exploitation depends on a server network using an operator-selected NAT64 prefix within the local-use range. A successful bypass can cross the intended network trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"fde10c1d4bbab706","cpes":["cpe:2.3:a:qs_project:qs:6.15.2:*:*:*:*:node.js:*:*"],"name":"qs","purl":"pkg:npm/qs@6.15.2","type":"npm","version":"6.15.2","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/qs@6.15.2/node_modules/qs/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/qs@6.15.2/node_modules/qs/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.16.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4mjr-xmp4-gh2g","versionConstraint":">=2.2.5,<6.16.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"qs","version":"6.15.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-4mjr-xmp4-gh2g","fix":{"state":"fixed","versions":["6.16.0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"6.16.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82417","cwe":"CWE-248","type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"},{"cve":"CVE-2026-82417","cwe":"CWE-703","type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"}],"epss":[{"cve":"CVE-2026-82417","date":"2026-10-08","epss":0.00418,"percentile":0.34075}],"risk":0.22572,"urls":["https://github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g","https://nvd.nist.gov/vuln/detail/CVE-2026-82417","https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4mjr-xmp4-gh2g","description":"qs: Denial of Service via Attacker Controlled isBuffer"},"relatedVulnerabilities":[{"id":"CVE-2026-82417","cvss":[{"type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82417","cwe":"CWE-248","type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"},{"cve":"CVE-2026-82417","cwe":"CWE-703","type":"Secondary","source":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"}],"epss":[{"cve":"CVE-2026-82417","date":"2026-10-08","epss":0.00418,"percentile":0.34075}],"urls":["https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6","https://github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82417","description":"### Summary\n\n\n\n`qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: \"x\" } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`.\n\n\n\n### Details\n\n\n\n`lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call.\n\n\n\nSuch an object can be built from untrusted input. `qs.parse(\"x[constructor][isBuffer]=y\", { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse(\"{\\\"a\\\":{\\\"constructor\\\":{\\\"isBuffer\\\":\\\"x\\\"}}}\")` produces the same shape with no qs option involved. Express 4 with its default `query parser` setting and body-parser with `extended: true` both call `qs.parse` with `allowPrototypes: true`, so on those stacks `req.query` and `req.body` can carry the shape directly.\n\n\n\n#### PoC\n\n\n\n```js\n\n\n\nvar qs = require(\"qs\");\n\n\n\nqs.stringify(qs.parse(\"x[constructor][isBuffer]=y\", { plainObjects: true }));\n\n\n\nqs.stringify(JSON.parse(\"{\\\"a\\\":{\\\"constructor\\\":{\\\"isBuffer\\\":\\\"x\\\"}}}\"));\n\n\n\n// TypeError: obj.constructor.isBuffer is not a function\n\n\n\n//     at Object.isBuffer (lib/utils.js:332:78)\n\n\n\n//     at stringify (lib/stringify.js:127:45)\n\n\n\n```\n\n\n\n#### Fix\n\n\n\n`lib/utils.js`, applied in e83d321 on `main` and released as v6.16.0:\n\n\n\n```diff\n\n\n\n- return !!(obj.constructor && obj.constructor.isBuffer && obj.constructor.isBuffer(obj));\n\n\n\n+ return !!(obj.constructor && typeof obj.constructor.isBuffer === \"function\" && obj.constructor.isBuffer(obj));\n\n\n\n```\n\n\n\nReal `Buffer`, `safer-buffer`, and browserify `buffer` polyfill instances serialize exactly as before; only the throw is removed.\n\n\n\n### Affected versions\n\n\n\n`>=2.2.5 <6.16.0`, fixed in v6.16.0.\n\n\n\nThe unguarded duck-type was introduced in 3768a75 and first shipped in v2.2.5 (September 2014). v2.2.4 and earlier used `Buffer.isBuffer` and are not affected. Every release from v2.2.5 through v6.15.3 contains the unguarded call.\n\n\n\n### Impact\n\n\n\nAn unauthenticated request can make any code path that re-serializes attacker-influenced data with `qs.stringify` (for example, rebuilding a query string from `req.query` for a redirect or an upstream request, or serializing a parsed JSON body) throw synchronously. In a typical Node.js HTTP framework the throw is caught by the framework error boundary and the affected request returns a 500; the process survives and other requests are unaffected. Where the call runs outside an error boundary, such as an `async` Express 4 handler (where the throw becomes an unhandled promise rejection) or a background job, the process exits, so the impact in that case depends on the application error handling rather than on qs."}]},{"artifact":{"id":"d601a8f22159af10","cpes":["cpe:2.3:a:nodejs:undici:6.27.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.27.0","type":"npm","version":"6.27.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3wwx-pv8p-q78v","versionConstraint":">=6.25.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.27.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3wwx-pv8p-q78v","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v","https://nvd.nist.gov/vuln/detail/CVE-2026-85024","https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c","https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6","https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3wwx-pv8p-q78v","description":"undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression"},"relatedVulnerabilities":[{"id":"CVE-2026-85024","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85024","description":"undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"1b9771ed454c8ce9","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3wwx-pv8p-q78v","versionConstraint":">=6.25.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3wwx-pv8p-q78v","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v","https://nvd.nist.gov/vuln/detail/CVE-2026-85024","https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c","https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6","https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3wwx-pv8p-q78v","description":"undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression"},"relatedVulnerabilities":[{"id":"CVE-2026-85024","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85024","description":"undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"fae15e6d4c5e7e92","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/undici@6.28.0/node_modules/undici/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/undici@6.28.0/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3wwx-pv8p-q78v","versionConstraint":">=6.25.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3wwx-pv8p-q78v","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v","https://nvd.nist.gov/vuln/detail/CVE-2026-85024","https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c","https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6","https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3wwx-pv8p-q78v","description":"undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression"},"relatedVulnerabilities":[{"id":"CVE-2026-85024","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85024","description":"undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"3b8f27c62542446d","cpes":["cpe:2.3:a:markdown-it_project:markdown-it:13.0.2:*:*:*:*:*:*:*"],"name":"markdown-it","purl":"pkg:npm/markdown-it@13.0.2","type":"npm","version":"13.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/markdown-it@13.0.2/node_modules/markdown-it/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/markdown-it@13.0.2/node_modules/markdown-it/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"14.2.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6v5v-wf23-fmfq","versionConstraint":"<=14.1.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"markdown-it","version":"13.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6v5v-wf23-fmfq","fix":{"state":"fixed","versions":["14.2.0"],"available":[{"date":"2026-06-16","kind":"first-observed","version":"14.2.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48988","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48988","date":"2026-10-08","epss":0.00432,"percentile":0.35397}],"risk":0.22248000000000004,"urls":["https://github.com/markdown-it/markdown-it/security/advisories/GHSA-6v5v-wf23-fmfq"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6v5v-wf23-fmfq","description":"markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations"},"relatedVulnerabilities":[{"id":"CVE-2026-48988","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48988","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48988","date":"2026-10-08","epss":0.00432,"percentile":0.35397}],"urls":["https://github.com/markdown-it/markdown-it/commit/9ce2087562c45d1e5ddd9f76b990f4b3fbe040e5","https://github.com/markdown-it/markdown-it/security/advisories/GHSA-6v5v-wf23-fmfq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48988","description":"markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per quote character. This can cause excessive CPU consumption when parsing quote-heavy, user-supplied markdown and may let attackers degrade or disrupt service availability. Although typographer is disabled by default, many production apps enable it for smart typography, making the issue relevant. This issue has been fixed in version 14.2.0."}]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m8m8-qj5v-23w3","versionConstraint":">=1.15.2,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-m8m8-qj5v-23w3","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101905","cwe":"CWE-441","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101905","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101905","date":"2026-10-08","epss":0.00289,"percentile":0.19674}],"risk":0.21819500000000003,"urls":["https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3","https://nvd.nist.gov/vuln/detail/CVE-2026-101905","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m8m8-qj5v-23w3","description":"Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection"},"relatedVulnerabilities":[{"id":"CVE-2026-101905","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101905","cwe":"CWE-441","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101905","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101905","date":"2026-10-08","epss":0.00289,"percentile":0.19674}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101905","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m8m8-qj5v-23w3","versionConstraint":">=1.15.2,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-m8m8-qj5v-23w3","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101905","cwe":"CWE-441","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101905","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101905","date":"2026-10-08","epss":0.00289,"percentile":0.19674}],"risk":0.21819500000000003,"urls":["https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3","https://nvd.nist.gov/vuln/detail/CVE-2026-101905","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m8m8-qj5v-23w3","description":"Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection"},"relatedVulnerabilities":[{"id":"CVE-2026-101905","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101905","cwe":"CWE-441","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101905","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101905","date":"2026-10-08","epss":0.00289,"percentile":0.19674}],"urls":["https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/releases/tag/v1.20.0","https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101905","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0."}]},{"artifact":{"id":"5e2ab97b23f852fa","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.2.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.2.0","type":"npm","version":"10.2.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rpw4-54j3-4h4q","versionConstraint":"<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rpw4-54j3-4h4q","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.21809,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q","https://nvd.nist.gov/vuln/detail/CVE-2026-101913","https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rpw4-54j3-4h4q","description":"ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts"},"relatedVulnerabilities":[{"id":"CVE-2026-101913","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101913","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlled address elsewhere in fe80::/10 can therefore pass a trust-boundary check that relies on isLinkLocal. The same address is identified as link-local by getType and getScope, exposing the inconsistent classification. A successful bypass can reach an on-link host outside the intended trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"ee4435d9da2328c8","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.3.1:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.3.1","type":"npm","version":"10.3.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rpw4-54j3-4h4q","versionConstraint":"<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.3.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rpw4-54j3-4h4q","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.21809,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q","https://nvd.nist.gov/vuln/detail/CVE-2026-101913","https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rpw4-54j3-4h4q","description":"ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts"},"relatedVulnerabilities":[{"id":"CVE-2026-101913","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101913","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlled address elsewhere in fe80::/10 can therefore pass a trust-boundary check that relies on isLinkLocal. The same address is identified as link-local by getType and getScope, exposing the inconsistent classification. A successful bypass can reach an on-link host outside the intended trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"aa86ffe12b42801d","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.3.1:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.3.1","type":"npm","version":"10.3.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/ip-address@10.3.1/node_modules/ip-address/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/ip-address@10.3.1/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rpw4-54j3-4h4q","versionConstraint":"<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.3.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rpw4-54j3-4h4q","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.21809,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q","https://nvd.nist.gov/vuln/detail/CVE-2026-101913","https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rpw4-54j3-4h4q","description":"ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts"},"relatedVulnerabilities":[{"id":"CVE-2026-101913","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101913","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlled address elsewhere in fe80::/10 can therefore pass a trust-boundary check that relies on isLinkLocal. The same address is identified as link-local by getType and getScope, exposing the inconsistent classification. A successful bypass can reach an on-link host outside the intended trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"419bb9cfaac3bb02","cpes":["cpe:2.3:a:libexpat:libexpat:2.8.3-r1:*:*:*:*:*:*:*"],"name":"libexpat","purl":"pkg:apk/alpine/libexpat@2.8.3-r1?arch=x86_64&distro=alpine-3.24&upstream=expat","type":"apk","version":"2.8.3-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libexpat.so.1"},{"path":"/usr/lib/libexpat.so.1.12.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"expat"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.8.4-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76956","versionConstraint":"< 2.8.4-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"expat","version":"2.8.3-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-76956","fix":{"state":"fixed","versions":["2.8.4-r0"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"2.8.4-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-08","epss":0.00287,"percentile":0.19503}],"risk":0.21525,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-76956"},"relatedVulnerabilities":[{"id":"CVE-2026-76956","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-08","epss":0.00287,"percentile":0.19503}],"urls":["https://github.com/libexpat/libexpat/pull/1326","https://github.com/libexpat/libexpat/pull/1329"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76956","description":"In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content."}]},{"artifact":{"id":"ee116feb549418a4","cpes":["cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector-parser:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*"],"name":"postcss-selector-parser","purl":"pkg:npm/postcss-selector-parser@7.1.4","type":"npm","version":"7.1.4","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rj75-hqrm-r3gf","versionConstraint":"<7.1.6 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"postcss-selector-parser","version":"7.1.4"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rj75-hqrm-r3gf","fix":{"state":"fixed","versions":["7.1.6"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"7.1.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104844","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104844","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104844","date":"2026-10-08","epss":0.00394,"percentile":0.31424}],"risk":0.21473,"urls":["https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf","https://nvd.nist.gov/vuln/detail/CVE-2026-104844","https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rj75-hqrm-r3gf","description":"PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-104844","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104844","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104844","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104844","date":"2026-10-08","epss":0.00394,"percentile":0.31424}],"urls":["https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6","https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104844","description":"PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a flat selector as one word token carrying many class or ID indexes because period and hash characters are not tokenizer word delimiters. The uniqs() deduplication and per-index class and ID membership checks repeatedly scan the class and ID index arrays, while a separate Sass-interpolation filtering pass also performs repeated linear scanning. Together, these passes make parsing quadratic in the number of indexes and allow a crafted selector to occupy a synchronous parser thread. The maxNestingDepth guard does not mitigate the issue because the hostile selector can have zero nesting depth. Only consumers that synchronously parse untrusted selectors in an exposed request path are affected; ordinary build-time parsing of trusted sources is not affected. This issue is fixed in version 7.1.6."}]},{"artifact":{"id":"6d0797d2a380fcd0","cpes":["cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector-parser:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*"],"name":"postcss-selector-parser","purl":"pkg:npm/postcss-selector-parser@7.1.4","type":"npm","version":"7.1.4","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rj75-hqrm-r3gf","versionConstraint":"<7.1.6 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"postcss-selector-parser","version":"7.1.4"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rj75-hqrm-r3gf","fix":{"state":"fixed","versions":["7.1.6"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"7.1.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104844","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104844","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104844","date":"2026-10-08","epss":0.00394,"percentile":0.31424}],"risk":0.21473,"urls":["https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf","https://nvd.nist.gov/vuln/detail/CVE-2026-104844","https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rj75-hqrm-r3gf","description":"PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-104844","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104844","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104844","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104844","date":"2026-10-08","epss":0.00394,"percentile":0.31424}],"urls":["https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6","https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104844","description":"PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a flat selector as one word token carrying many class or ID indexes because period and hash characters are not tokenizer word delimiters. The uniqs() deduplication and per-index class and ID membership checks repeatedly scan the class and ID index arrays, while a separate Sass-interpolation filtering pass also performs repeated linear scanning. Together, these passes make parsing quadratic in the number of indexes and allow a crafted selector to occupy a synchronous parser thread. The maxNestingDepth guard does not mitigate the issue because the hostile selector can have zero nesting depth. Only consumers that synchronously parse untrusted selectors in an exposed request path are affected; ordinary build-time parsing of trusted sources is not affected. This issue is fixed in version 7.1.6."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-75803"},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-75803"},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"5e2ab97b23f852fa","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.2.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.2.0","type":"npm","version":"10.2.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j6r3-76f7-8jcv","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j6r3-76f7-8jcv","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-08","epss":0.0037,"percentile":0.28846}],"risk":0.20904999999999999,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv","https://nvd.nist.gov/vuln/detail/CVE-2026-101912","https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j6r3-76f7-8jcv","description":"ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range"},"relatedVulnerabilities":[{"id":"CVE-2026-101912","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-08","epss":0.0037,"percentile":0.28846}],"urls":["https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101912","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both operands use the same IP family. A cross-family containment check whose leading address bits match makes the masked strings compare equal even though IPv4 and IPv6 do not share an address space. An allowlist or denylist decision can therefore classify an address outside the intended range as contained. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"ee4435d9da2328c8","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.3.1:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.3.1","type":"npm","version":"10.3.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j6r3-76f7-8jcv","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.3.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j6r3-76f7-8jcv","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-08","epss":0.0037,"percentile":0.28846}],"risk":0.20904999999999999,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv","https://nvd.nist.gov/vuln/detail/CVE-2026-101912","https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j6r3-76f7-8jcv","description":"ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range"},"relatedVulnerabilities":[{"id":"CVE-2026-101912","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-08","epss":0.0037,"percentile":0.28846}],"urls":["https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101912","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both operands use the same IP family. A cross-family containment check whose leading address bits match makes the masked strings compare equal even though IPv4 and IPv6 do not share an address space. An allowlist or denylist decision can therefore classify an address outside the intended range as contained. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"aa86ffe12b42801d","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.3.1:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.3.1","type":"npm","version":"10.3.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/ip-address@10.3.1/node_modules/ip-address/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/ip-address@10.3.1/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j6r3-76f7-8jcv","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.3.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j6r3-76f7-8jcv","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-08","epss":0.0037,"percentile":0.28846}],"risk":0.20904999999999999,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv","https://nvd.nist.gov/vuln/detail/CVE-2026-101912","https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j6r3-76f7-8jcv","description":"ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range"},"relatedVulnerabilities":[{"id":"CVE-2026-101912","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-08","epss":0.0037,"percentile":0.28846}],"urls":["https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101912","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both operands use the same IP family. A cross-family containment check whose leading address bits match makes the masked strings compare equal even though IPv4 and IPv6 do not share an address space. An allowlist or denylist decision can therefore classify an address outside the intended range as contained. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"afa69f01b5a5aaac","cpes":["cpe:2.3:a:pcre2:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.47-r1:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.47-r1?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.47-r1","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.15.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.7"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"fixed","versions":["10.48-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"10.48-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.20711,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"1c6d2c226c0741b3","cpes":["cpe:2.3:a:sprintf-js:sprintf-js:1.0.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf-js:sprintf_js:1.0.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf_js:sprintf-js:1.0.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf_js:sprintf_js:1.0.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf:sprintf-js:1.0.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf:sprintf_js:1.0.3:*:*:*:*:*:*:*","cpe:2.3:a:alexei:sprintf-js:1.0.3:*:*:*:*:*:*:*","cpe:2.3:a:alexei:sprintf_js:1.0.3:*:*:*:*:*:*:*"],"name":"sprintf-js","purl":"pkg:npm/sprintf-js@1.0.3","type":"npm","version":"1.0.3","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/sprintf-js@1.0.3/node_modules/sprintf-js/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/sprintf-js@1.0.3/node_modules/sprintf-js/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hp3w-g68c-fv3c","versionConstraint":"<=1.1.3 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"sprintf-js","version":"1.0.3"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-hp3w-g68c-fv3c","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97058","cwe":"CWE-1284","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-97058","date":"2026-10-08","epss":0.00366,"percentile":0.28365}],"risk":0.20312999999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-97058","https://github.com/alexei/sprintf.js/issues/237","https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L17","https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L84-L90","https://www.vulncheck.com/advisories/sprintf-js-through-1.1.3-denial-of-service-via-unbounded-precision"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hp3w-g68c-fv3c","description":"sprintf-js vulnerable to denial of service through unbounded precision specifiers"},"relatedVulnerabilities":[{"id":"CVE-2026-97058","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97058","cwe":"CWE-1284","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-97058","date":"2026-10-08","epss":0.00366,"percentile":0.28365}],"urls":["https://github.com/alexei/sprintf.js","https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L17","https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L84-L90","https://github.com/alexei/sprintf.js/issues/237","https://www.vulncheck.com/advisories/sprintf-js-through-1.1.3-denial-of-service-via-unbounded-precision"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97058","description":"sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload."}]},{"artifact":{"id":"94bdf0044f06b439","cpes":["cpe:2.3:a:sprintf-js:sprintf-js:1.1.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf-js:sprintf_js:1.1.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf_js:sprintf-js:1.1.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf_js:sprintf_js:1.1.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf:sprintf-js:1.1.3:*:*:*:*:*:*:*","cpe:2.3:a:sprintf:sprintf_js:1.1.3:*:*:*:*:*:*:*","cpe:2.3:a:alexei:sprintf-js:1.1.3:*:*:*:*:*:*:*","cpe:2.3:a:alexei:sprintf_js:1.1.3:*:*:*:*:*:*:*"],"name":"sprintf-js","purl":"pkg:npm/sprintf-js@1.1.3","type":"npm","version":"1.1.3","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/sprintf-js@1.1.3/node_modules/sprintf-js/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/sprintf-js@1.1.3/node_modules/sprintf-js/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hp3w-g68c-fv3c","versionConstraint":"<=1.1.3 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"sprintf-js","version":"1.1.3"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-hp3w-g68c-fv3c","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97058","cwe":"CWE-1284","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-97058","date":"2026-10-08","epss":0.00366,"percentile":0.28365}],"risk":0.20312999999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-97058","https://github.com/alexei/sprintf.js/issues/237","https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L17","https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L84-L90","https://www.vulncheck.com/advisories/sprintf-js-through-1.1.3-denial-of-service-via-unbounded-precision"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hp3w-g68c-fv3c","description":"sprintf-js vulnerable to denial of service through unbounded precision specifiers"},"relatedVulnerabilities":[{"id":"CVE-2026-97058","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97058","cwe":"CWE-1284","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-97058","date":"2026-10-08","epss":0.00366,"percentile":0.28365}],"urls":["https://github.com/alexei/sprintf.js","https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L17","https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L84-L90","https://github.com/alexei/sprintf.js/issues/237","https://www.vulncheck.com/advisories/sprintf-js-through-1.1.3-denial-of-service-via-unbounded-precision"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97058","description":"sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload."}]},{"artifact":{"id":"3c2cf04a1811dafc","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"ab5593bbdf9ba16a","cpes":["cpe:2.3:a:momentjs:moment:2.30.1:*:*:*:*:node.js:*:*"],"name":"moment","purl":"pkg:npm/moment@2.30.1","type":"npm","version":"2.30.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/moment@2.30.1/node_modules/moment/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/moment@2.30.1/node_modules/moment/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.31.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4p3w-j4w9-5jqw","versionConstraint":">=2.29.2,<2.31.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"moment","version":"2.30.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-4p3w-j4w9-5jqw","fix":{"state":"fixed","versions":["2.31.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.31.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17495","cwe":"CWE-27","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-17495","date":"2026-10-08","epss":0.00357,"percentile":0.2734}],"risk":0.194565,"urls":["https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw","https://nvd.nist.gov/vuln/detail/CVE-2026-17495","https://github.com/moment/moment/pull/6386","https://github.com/moment/moment/commit/5f7d983c9881e65e07574de9dda3190d99520c07","https://cna.openjsf.org/security-advisories.html","https://github.com/moment/moment/releases/tag/2.31.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4p3w-j4w9-5jqw","description":"moment vulnerable to Path Traversal via crafted non-string locale name"},"relatedVulnerabilities":[{"id":"CVE-2026-17495","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17495","cwe":"CWE-27","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-17495","date":"2026-10-08","epss":0.00357,"percentile":0.2734}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17495","description":"moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale()."}]},{"artifact":{"id":"34a0a5e3ece0fdd0","cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:tiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:tiff:4.7.1-r0:*:*:*:*:*:*:*"],"name":"tiff","purl":"pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"4.7.1-r0","language":"","licenses":["libtiff"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libtiff.so.6"},{"path":"/usr/lib/libtiff.so.6.2.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"tiff"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6228","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1:*:*:*:*:*:*:*"],"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6228","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6228","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6228","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6228","date":"2026-10-08","epss":0.00399,"percentile":0.32024}],"risk":0.18752999999999997,"urls":["https://access.redhat.com/errata/RHSA-2024:2289","https://access.redhat.com/errata/RHSA-2024:5079","https://access.redhat.com/security/cve/CVE-2023-6228","https://bugzilla.redhat.com/show_bug.cgi?id=2240995"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6228","description":"An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash."},"relatedVulnerabilities":[]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"93f929590853fc8f","cpes":["cpe:2.3:a:showdownjs:showdown:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:showdown:showdown:2.1.0:*:*:*:*:*:*:*"],"name":"showdown","purl":"pkg:npm/showdown@2.1.0","type":"npm","version":"2.1.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/showdown@2.1.0/node_modules/showdown/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/showdown@2.1.0/node_modules/showdown/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-22g5-r2x5-97cx","versionConstraint":"<=2.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"showdown","version":"2.1.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-22g5-r2x5-97cx","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59710","cwe":"CWE-79","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-59710","date":"2026-10-08","epss":0.00338,"percentile":0.2515}],"risk":0.18083,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-59710","https://github.com/showdownjs/showdown/issues/1046","https://github.com/showdownjs/showdown/commit/e5cab1e9a5dcea2bb3cbf888863fa7e65ab37edf","https://github.com/showdownjs/showdown","https://www.vulncheck.com/advisories/showdown-stored-xss-via-unescaped-table-header-id-attribute-injection"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-22g5-r2x5-97cx","description":"showdown allows stored cross-site scripting through table header ID injection"},"relatedVulnerabilities":[{"id":"CVE-2026-59710","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59710","cwe":"CWE-79","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-59710","date":"2026-10-08","epss":0.00338,"percentile":0.2515}],"urls":["https://github.com/showdownjs/showdown","https://github.com/showdownjs/showdown/commit/e5cab1e9a5dcea2bb3cbf888863fa7e65ab37edf","https://github.com/showdownjs/showdown/issues/1046","https://www.vulncheck.com/advisories/showdown-stored-xss-via-unescaped-table-header-id-attribute-injection"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59710","description":"showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration."}]},{"artifact":{"id":"9f5ce00623e7a21a","cpes":["cpe:2.3:a:openjsf:fast-uri:3.1.6:*:*:*:*:node.js:*:*"],"name":"fast-uri","purl":"pkg:npm/fast-uri@3.1.6","type":"npm","version":"3.1.6","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/fast-uri@3.1.6/node_modules/fast-uri/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/fast-uri@3.1.6/node_modules/fast-uri/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qw65-cvwx-89v3","versionConstraint":">=3.0.0,<3.1.7 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"fast-uri","version":"3.1.6"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-qw65-cvwx-89v3","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84292","cwe":"CWE-116","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-84292","date":"2026-10-08","epss":0.00239,"percentile":0.13752}],"risk":0.17925000000000002,"urls":["https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3","https://nvd.nist.gov/vuln/detail/CVE-2026-84292","https://github.com/fastify/fast-uri/commit/820e8478dd7da3d09f187bfaf35d50b71f67b8b4","https://cna.openjsf.org/security-advisories.html","https://github.com/fastify/fast-uri/releases/tag/v2.4.6","https://github.com/fastify/fast-uri/releases/tag/v3.1.7","https://github.com/fastify/fast-uri/releases/tag/v4.1.4"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qw65-cvwx-89v3","description":"fast-uri vulnerable to authority injection via an unvalidated port in serialize"},"relatedVulnerabilities":[{"id":"CVE-2026-84292","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84292","cwe":"CWE-116","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-84292","date":"2026-10-08","epss":0.00239,"percentile":0.13752}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84292","description":"fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986."}]},{"artifact":{"id":"93f929590853fc8f","cpes":["cpe:2.3:a:showdownjs:showdown:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:showdown:showdown:2.1.0:*:*:*:*:*:*:*"],"name":"showdown","purl":"pkg:npm/showdown@2.1.0","type":"npm","version":"2.1.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/showdown@2.1.0/node_modules/showdown/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/showdown@2.1.0/node_modules/showdown/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cr32-g25g-vxjj","versionConstraint":"<=2.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"showdown","version":"2.1.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-cr32-g25g-vxjj","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59711","cwe":"CWE-79","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-59711","date":"2026-10-08","epss":0.00327,"percentile":0.23751}],"risk":0.17494499999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-59711","https://github.com/showdownjs/showdown/issues/1047","https://github.com/showdownjs/showdown","https://www.vulncheck.com/advisories/showdown-cross-site-scripting-via-unescaped-metadata-title-in-completehtmldocument","https://github.com/showdownjs/showdown/commit/184a3e4e97f90e075c4512f2c4c06dcf655e91b7"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cr32-g25g-vxjj","description":"showdown metadata title handling allows cross-site scripting"},"relatedVulnerabilities":[{"id":"CVE-2026-59711","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59711","cwe":"CWE-79","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-59711","date":"2026-10-08","epss":0.00327,"percentile":0.23751}],"urls":["https://github.com/showdownjs/showdown","https://github.com/showdownjs/showdown/issues/1047","https://www.vulncheck.com/advisories/showdown-cross-site-scripting-via-unescaped-metadata-title-in-completehtmldocument"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59711","description":"showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page."}]},{"artifact":{"id":"5e2ab97b23f852fa","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.2.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.2.0","type":"npm","version":"10.2.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3mg-xc3c-68pw","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-h3mg-xc3c-68pw","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-08","epss":0.00301,"percentile":0.20955}],"risk":0.170065,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw","https://nvd.nist.gov/vuln/detail/CVE-2026-101911","https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3mg-xc3c-68pw","description":"ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process"},"relatedVulnerabilities":[{"id":"CVE-2026-101911","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-08","epss":0.00301,"percentile":0.20955}],"urls":["https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101911","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"ee4435d9da2328c8","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.3.1:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.3.1","type":"npm","version":"10.3.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3mg-xc3c-68pw","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.3.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-h3mg-xc3c-68pw","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-08","epss":0.00301,"percentile":0.20955}],"risk":0.170065,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw","https://nvd.nist.gov/vuln/detail/CVE-2026-101911","https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3mg-xc3c-68pw","description":"ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process"},"relatedVulnerabilities":[{"id":"CVE-2026-101911","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-08","epss":0.00301,"percentile":0.20955}],"urls":["https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101911","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"aa86ffe12b42801d","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.3.1:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.3.1","type":"npm","version":"10.3.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/ip-address@10.3.1/node_modules/ip-address/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/ip-address@10.3.1/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3mg-xc3c-68pw","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.3.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-h3mg-xc3c-68pw","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-08","epss":0.00301,"percentile":0.20955}],"risk":0.170065,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw","https://nvd.nist.gov/vuln/detail/CVE-2026-101911","https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3mg-xc3c-68pw","description":"ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process"},"relatedVulnerabilities":[{"id":"CVE-2026-101911","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-08","epss":0.00301,"percentile":0.20955}],"urls":["https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101911","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60001"},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60001"},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60001"},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60001"},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60001"},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60001"},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-60001"},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"afa69f01b5a5aaac","cpes":["cpe:2.3:a:pcre2:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.47-r1:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.47-r1?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.47-r1","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.15.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.7"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.49-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"< 10.49-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.49-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"< 10.49-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"fixed","versions":["10.49-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"10.49-r0"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.16157000000000002,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"afa69f01b5a5aaac","cpes":["cpe:2.3:a:pcre2:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.47-r1:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.47-r1?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.47-r1","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.15.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.7"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"fixed","versions":["10.48-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"10.48-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.16023,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"416a9506ffa9ec40","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.1.4:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.1.4","type":"npm","version":"2.1.4","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@2.1.4/node_modules/brace-expansion/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@2.1.4/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q2hr-2g5m-vwhr","versionConstraint":">=2.0.0,<2.1.7 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.1.4"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-q2hr-2g5m-vwhr","fix":{"state":"fixed","versions":["2.1.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"risk":0.15501500000000001,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr","https://nvd.nist.gov/vuln/detail/CVE-2026-102277","https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q2hr-2g5m-vwhr","description":"brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-102277","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"urls":["https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102277","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12."}]},{"artifact":{"id":"9b333847e4cf6c68","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.7:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.7","type":"npm","version":"5.0.7","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q2hr-2g5m-vwhr","versionConstraint":">=4.0.0,<5.0.12 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.7"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-q2hr-2g5m-vwhr","fix":{"state":"fixed","versions":["5.0.12"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"risk":0.15501500000000001,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr","https://nvd.nist.gov/vuln/detail/CVE-2026-102277","https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q2hr-2g5m-vwhr","description":"brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-102277","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"urls":["https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102277","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12."}]},{"artifact":{"id":"4ab07d6591eefe2f","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@5.0.9/node_modules/brace-expansion/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/brace-expansion@5.0.9/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q2hr-2g5m-vwhr","versionConstraint":">=4.0.0,<5.0.12 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-q2hr-2g5m-vwhr","fix":{"state":"fixed","versions":["5.0.12"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"risk":0.15501500000000001,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr","https://nvd.nist.gov/vuln/detail/CVE-2026-102277","https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q2hr-2g5m-vwhr","description":"brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-102277","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"urls":["https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102277","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12."}]},{"artifact":{"id":"10dadf83fd0e284c","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q2hr-2g5m-vwhr","versionConstraint":">=4.0.0,<5.0.12 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-q2hr-2g5m-vwhr","fix":{"state":"fixed","versions":["5.0.12"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"risk":0.15501500000000001,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr","https://nvd.nist.gov/vuln/detail/CVE-2026-102277","https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q2hr-2g5m-vwhr","description":"brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-102277","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"urls":["https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102277","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12."}]},{"artifact":{"id":"8092b16b55387366","cpes":["cpe:2.3:a:grpc:grpc:1.14.4:*:*:*:*:node.js:*:*"],"name":"@grpc/grpc-js","purl":"pkg:npm/%40grpc/grpc-js@1.14.4","type":"npm","version":"1.14.4","language":"javascript","licenses":["Apache-2.0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@grpc+grpc-js@1.14.4/node_modules/@grpc/grpc-js/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@grpc+grpc-js@1.14.4/node_modules/@grpc/grpc-js/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.14.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m9gg-hp2v-232j","versionConstraint":">=1.14.0,<1.14.5 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@grpc/grpc-js","version":"1.14.4"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-m9gg-hp2v-232j","fix":{"state":"fixed","versions":["1.14.5"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.14.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101916","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101916","date":"2026-10-08","epss":0.00208,"percentile":0.09945}],"risk":0.15496,"urls":["https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j","https://nvd.nist.gov/vuln/detail/CVE-2026-101916","https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee","https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c","https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m9gg-hp2v-232j","description":"@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized"},"relatedVulnerabilities":[{"id":"CVE-2026-101916","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101916","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101916","date":"2026-10-08","epss":0.00208,"percentile":0.09945}],"urls":["https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee","https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c","https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5","https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101916","description":"@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6."}]},{"artifact":{"id":"afa69f01b5a5aaac","cpes":["cpe:2.3:a:pcre2:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.47-r1:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.47-r1?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.47-r1","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.15.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.7"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"fixed","versions":["10.48-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"10.48-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.1541,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"bb3bb0d123bb84ee","cpes":["cpe:2.3:a:handlebars.js_project:handlebars.js:4.7.9:*:*:*:*:node.js:*:*","cpe:2.3:a:handlebarsjs:handlebars:4.7.9:*:*:*:*:node.js:*:*"],"name":"handlebars","purl":"pkg:npm/handlebars@4.7.9","type":"npm","version":"4.7.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/handlebars@4.7.9/node_modules/handlebars/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/handlebars@4.7.9/node_modules/handlebars/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.7.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xw65-4hp5-5hc7","versionConstraint":">=4.0.0,<=4.7.9 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"handlebars","version":"4.7.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-xw65-4hp5-5hc7","fix":{"state":"fixed","versions":["4.7.10"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"4.7.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.7,"impactScore":2.8,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106444","cwe":"CWE-116","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106444","date":"2026-10-08","epss":0.00294,"percentile":0.20227}],"risk":0.14259,"urls":["https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-xw65-4hp5-5hc7","https://nvd.nist.gov/vuln/detail/CVE-2026-106444","https://github.com/handlebars-lang/handlebars.js/pull/2185","https://github.com/handlebars-lang/handlebars.js/commit/609d1b11c833c9a3e00f56f2f34d22f425446725","https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xw65-4hp5-5hc7","description":"Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates"},"relatedVulnerabilities":[{"id":"CVE-2026-106444","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.7,"impactScore":2.8,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106444","cwe":"CWE-116","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106444","date":"2026-10-08","epss":0.00294,"percentile":0.20227}],"urls":["https://github.com/handlebars-lang/handlebars.js/commit/609d1b11c833c9a3e00f56f2f34d22f425446725","https://github.com/handlebars-lang/handlebars.js/pull/2185","https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10","https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-xw65-4hp5-5hc7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106444","description":"Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10."}]},{"artifact":{"id":"afa69f01b5a5aaac","cpes":["cpe:2.3:a:pcre2:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.47-r1:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.47-r1?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.47-r1","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.15.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.7"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"fixed","versions":["10.48-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"10.48-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.14202499999999998,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35189","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35189","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7772b4d6519da701","cpes":["cpe:2.3:a:element-plus:element-plus:2.4.3:*:*:*:*:*:*:*","cpe:2.3:a:element-plus:element_plus:2.4.3:*:*:*:*:*:*:*","cpe:2.3:a:element_plus:element-plus:2.4.3:*:*:*:*:*:*:*","cpe:2.3:a:element_plus:element_plus:2.4.3:*:*:*:*:*:*:*","cpe:2.3:a:element:element-plus:2.4.3:*:*:*:*:*:*:*","cpe:2.3:a:element:element_plus:2.4.3:*:*:*:*:*:*:*"],"name":"element-plus","purl":"pkg:npm/element-plus@2.4.3","type":"npm","version":"2.4.3","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/element-plus@2.4.3_patch_hash=95b9793afc4529bc887bf7dac437131975e133feb7152dce68aa4b3c9_f2e333df73e02df285fe0bca1f85e315/node_modules/element-plus/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/element-plus@2.4.3_patch_hash=95b9793afc4529bc887bf7dac437131975e133feb7152dce68aa4b3c9_f2e333df73e02df285fe0bca1f85e315/node_modules/element-plus/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5m5x-9j46-h678","versionConstraint":"<=2.11.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"element-plus","version":"2.4.3"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-5m5x-9j46-h678","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-57665","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-57665","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-57665","date":"2026-10-08","epss":0.00236,"percentile":0.13411}],"risk":0.13688,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-57665","https://github.com/element-plus/element-plus/pull/21711","https://element-plus.org/en-US/component/link.html","https://github.com/element-plus/element-plus","https://github.com/element-plus/element-plus/blob/dev/packages/components/link/src/link.vue","https://www.npmjs.com/package/element-plus","https://github.com/element-plus/element-plus/commit/110d4e1d7e150ccb829771c7319d31ce777d102f"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5m5x-9j46-h678","description":"Element Plus Link component (el-link) implements insufficient input validation for the href attribute"},"relatedVulnerabilities":[{"id":"CVE-2025-57665","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.4,"impactScore":2.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-57665","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-57665","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-57665","date":"2026-10-08","epss":0.00236,"percentile":0.13411}],"urls":["https://element-plus.org/en-US/component/link.html","https://github.com/element-plus/element-plus","https://github.com/element-plus/element-plus/blob/dev/packages/components/link/src/link.vue","https://github.com/element-plus/element-plus/pull/21711","https://www.npmjs.com/package/element-plus"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-57665","description":"Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL sanitization, or security headers. This allows attackers to inject malicious URLs using dangerous protocols (javascript:, data:, file:) or redirect users to external malicious sites. While native HTML anchor elements present similar risks, UI component libraries bear additional responsibility for implementing security safeguards and providing clear risk documentation. The vulnerability enables XSS attacks, phishing campaigns, and open redirect exploits affecting applications that use Element Plus Link components with user-controlled or untrusted URL inputs."}]},{"artifact":{"id":"2e1fbe3c5698a687","cpes":["cpe:2.3:a:\\@modelcontextprotocol\\/sdk:\\@modelcontextprotocol\\/sdk:1.26.0:*:*:*:*:*:*:*"],"name":"@modelcontextprotocol/sdk","purl":"pkg:npm/%40modelcontextprotocol/sdk@1.26.0","type":"npm","version":"1.26.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@modelcontextprotocol+sdk@1.26.0_supports-color@8.1.1_zod@3.25.76/node_modules/@modelcontextprotocol/sdk/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@modelcontextprotocol+sdk@1.26.0_supports-color@8.1.1_zod@3.25.76/node_modules/@modelcontextprotocol/sdk/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.31.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6qxp-vccf-f47h","versionConstraint":">=1.12.0,<1.31.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@modelcontextprotocol/sdk","version":"1.26.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6qxp-vccf-f47h","fix":{"state":"fixed","versions":["1.31.0"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.31.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104850","cwe":"CWE-345","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104850","cwe":"CWE-522","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104850","date":"2026-10-08","epss":0.00176,"percentile":0.06479}],"risk":0.132,"urls":["https://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-6qxp-vccf-f47h","https://github.com/modelcontextprotocol/typescript-sdk/pull/2887","https://github.com/modelcontextprotocol/typescript-sdk/commit/edd12e282620ebf770d67316f19cf91d4112a1bd","https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/v2.2.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6qxp-vccf-f47h","description":"MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server"},"relatedVulnerabilities":[{"id":"CVE-2026-104850","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104850","cwe":"CWE-345","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104850","cwe":"CWE-522","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104850","date":"2026-10-08","epss":0.00176,"percentile":0.06479}],"urls":["https://github.com/modelcontextprotocol/typescript-sdk/commit/edd12e282620ebf770d67316f19cf91d4112a1bd","https://github.com/modelcontextprotocol/typescript-sdk/pull/2887","https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/v2.2.0","https://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-6qxp-vccf-f47h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104850","description":"MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth credentials. Stored and pre-provisioned credentials were not bound to the authorization server they belong to. A malicious or compromised MCP server could name its own authorization server in its protected resource metadata. Without any user interaction, the client would send that server the `refresh_token` and `client_secret` stored from an earlier sign-in (1.x), or the configured `client_secret` or signed assertion of a bundled non-interactive provider (1.x and 2.x). Only those applications that use the SDK as an MCP client over HTTP with an `authProvider`: your own `OAuthClientProvider`, or the bundled `ClientCredentialsProvider`, `PrivateKeyJwtProvider`, `StaticPrivateKeyJwtProvider` or (2.x) `CrossAppAccessProvider` and that may connect to an MCP server the owners does not fully trust while holding credentials for a legitimate authorization server are affected. `@modelcontextprotocol/sdk` 1.31.0 (1.x) and `@modelcontextprotocol/client` 2.2.0 (2.x) patch the issue. A workaround for those who cannot upgrade is available. 2.0.0 and 2.1.0 already accept `expectedIssuer`. On 1.x, the only workaround is to connect OAuth-enabled clients only to MCP servers you trust."}]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59995"},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59996"},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59995"},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59996"},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59995"},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59996"},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59995"},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59996"},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59995"},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59996"},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59995"},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59996"},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59995"},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59996"},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"9f5ce00623e7a21a","cpes":["cpe:2.3:a:openjsf:fast-uri:3.1.6:*:*:*:*:node.js:*:*"],"name":"fast-uri","purl":"pkg:npm/fast-uri@3.1.6","type":"npm","version":"3.1.6","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/fast-uri@3.1.6/node_modules/fast-uri/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/fast-uri@3.1.6/node_modules/fast-uri/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.1.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hrr3-gc8f-f4qj","versionConstraint":">=3.0.0,<3.1.8 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"fast-uri","version":"3.1.6"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-hrr3-gc8f-f4qj","fix":{"state":"fixed","versions":["3.1.8"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.1.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86472","cwe":"CWE-178","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-86472","date":"2026-10-08","epss":0.00253,"percentile":0.15369}],"risk":0.12397000000000001,"urls":["https://github.com/fastify/fast-uri/security/advisories/GHSA-hrr3-gc8f-f4qj","https://nvd.nist.gov/vuln/detail/CVE-2026-86472","https://github.com/fastify/fast-uri/commit/5dabb86732aa2a7655e258719970e61e12b6b4d1","https://cna.openjsf.org/security-advisories.html","https://github.com/fastify/fast-uri/releases/tag/v2.4.7","https://github.com/fastify/fast-uri/releases/tag/v3.1.8","https://github.com/fastify/fast-uri/releases/tag/v4.1.5"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hrr3-gc8f-f4qj","description":"fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets"},"relatedVulnerabilities":[{"id":"CVE-2026-86472","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86472","cwe":"CWE-178","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-86472","date":"2026-10-08","epss":0.00253,"percentile":0.15369}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/fastify/fast-uri/security/advisories/GHSA-hrr3-gc8f-f4qj"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86472","description":"fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase octet such as %41 decodes to a literal A that is never folded. For a scheme-relative reference such as //host there is no scheme, so the host canonicalization that would normally repair this does not run, and parse, normalize, and equal then disagree on the same host. An application that makes a case-sensitive host decision on fast-uri output, for example a host allowlist or denylist that compares the parsed host or uses equal, can be steered past the check with a percent-encoded uppercase octet, and because hostnames are case-insensitive in DNS and HTTP the evading spelling still reaches the host the check meant to gate. The issue is fixed in fast-uri 2.4.7, 3.1.8, and 4.1.5, and users should upgrade to one of those versions or later. As a workaround, compare hosts case-insensitively by lowercasing the parsed host before any allowlist or denylist decision."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35191","versionConstraint":">= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35191","versionConstraint":">= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59999"},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59999"},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59999"},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59999"},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59999"},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59999"},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59999"},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75805","versionConstraint":">= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75805","versionConstraint":">= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"f177012132788aa6","cpes":["cpe:2.3:a:hono:hono:4.12.34:*:*:*:*:node.js:*:*"],"name":"hono","purl":"pkg:npm/hono@4.12.34","type":"npm","version":"4.12.34","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/hono@4.12.34/node_modules/hono/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/hono@4.12.34/node_modules/hono/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.13.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hxh3-vqpv-xpqv","versionConstraint":"<4.13.7 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"hono","version":"4.12.34"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-hxh3-vqpv-xpqv","fix":{"state":"fixed","versions":["4.13.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"4.13.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.7,"impactScore":2.8,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93981","cwe":"CWE-79","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93981","date":"2026-10-08","epss":0.00227,"percentile":0.12409}],"risk":0.11009499999999998,"urls":["https://github.com/honojs/hono/security/advisories/GHSA-hxh3-vqpv-xpqv","https://nvd.nist.gov/vuln/detail/CVE-2026-93981","https://github.com/honojs/hono/commit/2b8ed402cdab6dfc5e829b480806dcd8db94161e","https://github.com/honojs/hono/releases/tag/v4.13.7","https://www.vulncheck.com/advisories/hono-jsx-before-4.13.7-cross-site-scripting-via-unescaped-strings"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hxh3-vqpv-xpqv","description":"hono/jsx renders plain strings unescaped in boundary components, leading to XSS"},"relatedVulnerabilities":[{"id":"CVE-2026-93981","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.7,"impactScore":2.8,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93981","cwe":"CWE-79","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93981","date":"2026-10-08","epss":0.00227,"percentile":0.12409}],"urls":["https://github.com/honojs/hono/security/advisories/GHSA-hxh3-vqpv-xpqv","https://www.vulncheck.com/advisories/hono-jsx-before-4.13.7-cross-site-scripting-via-unescaped-strings"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93981","description":"hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the root value passed to renderToString() or renderToReadableStream() from hono/jsx/dom/server. These paths stringify their input and treat the result as already-escaped markup, so an attacker who controls such a string during server-side rendering can inject arbitrary HTML and execute script under the application's origin."}]},{"artifact":{"id":"31a0e0e0d1265f89","cpes":["cpe:2.3:a:adm-zip_project:adm-zip:0.6.0:*:*:*:*:node.js:*:*"],"name":"adm-zip","purl":"pkg:npm/adm-zip@0.6.0","type":"npm","version":"0.6.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j5f4-cc29-5x44","versionConstraint":"<=0.6.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"adm-zip","version":"0.6.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j5f4-cc29-5x44","fix":{"state":"fixed","versions":["0.6.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"0.6.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102282","cwe":"CWE-732","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102282","date":"2026-10-08","epss":0.00149,"percentile":0.03587}],"risk":0.10877,"urls":["https://github.com/cthackers/adm-zip/security/advisories/GHSA-j5f4-cc29-5x44","https://github.com/cthackers/adm-zip/commit/6a63c339b83c52915483efacda517660a7a7bf87","https://github.com/cthackers/adm-zip/releases/tag/v0.6.1"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j5f4-cc29-5x44","description":"adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation"},"relatedVulnerabilities":[{"id":"CVE-2026-102282","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102282","cwe":"CWE-732","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102282","date":"2026-10-08","epss":0.00149,"percentile":0.03587}],"urls":["https://github.com/cthackers/adm-zip/commit/6a63c339b83c52915483efacda517660a7a7bf87","https://github.com/cthackers/adm-zip/releases/tag/v0.6.1","https://github.com/cthackers/adm-zip/security/advisories/GHSA-j5f4-cc29-5x44"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102282","description":"adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue."}]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59998"},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59998"},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59998"},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59998"},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59998"},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59998"},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59998"},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"31a0e0e0d1265f89","cpes":["cpe:2.3:a:adm-zip_project:adm-zip:0.6.0:*:*:*:*:node.js:*:*"],"name":"adm-zip","purl":"pkg:npm/adm-zip@0.6.0","type":"npm","version":"0.6.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vwc7-r8mq-g2x9","versionConstraint":">=0.5.9,<=0.6.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"adm-zip","version":"0.6.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-vwc7-r8mq-g2x9","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76845","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76845","date":"2026-10-08","epss":0.00171,"percentile":0.05864}],"risk":0.09960749999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-76845","https://github.com/cthackers/adm-zip","https://github.com/cthackers/adm-zip/blob/v0.6.0/util/utils.js","https://www.vulncheck.com/advisories/adm-zip-through-arbitrary-file-overwrite-via-symlink-following-on-extraction","https://github.com/cthackers/adm-zip/issues/574","https://github.com/cthackers/adm-zip/pull/575"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vwc7-r8mq-g2x9","description":"adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite"},"relatedVulnerabilities":[{"id":"CVE-2026-76845","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76845","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76845","date":"2026-10-08","epss":0.00171,"percentile":0.05864}],"urls":["https://github.com/cthackers/adm-zip","https://github.com/cthackers/adm-zip/blob/v0.6.0/util/utils.js","https://www.vulncheck.com/advisories/adm-zip-through-arbitrary-file-overwrite-via-symlink-following-on-extraction"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76845","description":"adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name against the resolved extraction root, and Utils.writeFileTo opens the computed destination with fs.openSync(path, \"w\", 0o666), which resolves symbolic links and carries neither O_NOFOLLOW nor a pre-write fs.lstatSync check. When a path component at the destination already exists as a symbolic link pointing outside the extraction root, extractAllTo, extractAllToAsync and extractEntryTo write the entry contents through that link and then chmod its target, placing attacker-controlled content in a file outside the root without any traversal sequence appearing in the archive. Reaching the write requires overwrite to be enabled, because the preceding fs.existsSync check also resolves the link and otherwise declines. An attacker able to create a symbolic link inside a shared, reused or predictable extraction directory, such as a temporary directory or a continuous integration workspace, can overwrite any file the extracting process is permitted to write."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54875","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54875","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"},"relatedVulnerabilities":[]},{"artifact":{"id":"de286a9b7e19b2a8","cpes":["cpe:2.3:a:stream-json:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream-json:stream_json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream_json:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream_json:stream_json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream:stream_json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:uhop:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:uhop:stream_json:1.9.1:*:*:*:*:*:*:*"],"name":"stream-json","purl":"pkg:npm/stream-json@1.9.1","type":"npm","version":"1.9.1","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/stream-json@1.9.1/node_modules/stream-json/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/stream-json@1.9.1/node_modules/stream-json/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mjw6-4jj6-33hc","versionConstraint":"<3.6.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"stream-json","version":"1.9.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-mjw6-4jj6-33hc","fix":{"state":"fixed","versions":["3.6.0"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"3.6.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.1,"impactScore":2.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104183","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104183","date":"2026-10-08","epss":0.00195,"percentile":0.08433}],"risk":0.098475,"urls":["https://github.com/uhop/stream-json/security/advisories/GHSA-mjw6-4jj6-33hc","https://nvd.nist.gov/vuln/detail/CVE-2026-104183","https://github.com/uhop/stream-json/commit/2f2d35bbb547306991ded6487a279154d865a358","https://github.com/uhop/stream-json/releases/tag/3.6.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mjw6-4jj6-33hc","description":"stream-json has a prototype pollution issue: Assembler writes this.current[this.key] on plain objects"},"relatedVulnerabilities":[{"id":"CVE-2026-104183","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.1,"impactScore":2.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104183","cwe":"CWE-1321","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104183","date":"2026-10-08","epss":0.00195,"percentile":0.08433}],"urls":["https://github.com/uhop/stream-json/commit/2f2d35bbb547306991ded6487a279154d865a358","https://github.com/uhop/stream-json/releases/tag/3.6.0","https://github.com/uhop/stream-json/security/advisories/GHSA-mjw6-4jj6-33hc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104183","description":"stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0."}]},{"artifact":{"id":"afa69f01b5a5aaac","cpes":["cpe:2.3:a:pcre2:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.47-r1:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.47-r1?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.47-r1","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.15.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.7"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"fixed","versions":["10.48-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"10.48-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.09639,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-89161"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"d601a8f22159af10","cpes":["cpe:2.3:a:nodejs:undici:6.27.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.27.0","type":"npm","version":"6.27.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v3r7-h72x-cjcm","versionConstraint":"<6.28.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.27.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-v3r7-h72x-cjcm","fix":{"state":"fixed","versions":["6.28.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"6.28.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16729","cwe":"CWE-74","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-16729","date":"2026-10-08","epss":0.00191,"percentile":0.07982}],"risk":0.09359,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm","https://nvd.nist.gov/vuln/detail/CVE-2026-16729","https://github.com/nodejs/undici/commit/10d93fc332f2c8c161982dec3833201de29891b5","https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef","https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.0","https://github.com/nodejs/undici/releases/tag/v7.29.0","https://github.com/nodejs/undici/releases/tag/v8.9.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v3r7-h72x-cjcm","description":"undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields"},"relatedVulnerabilities":[{"id":"CVE-2026-16729","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16729","cwe":"CWE-74","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-16729","date":"2026-10-08","epss":0.00191,"percentile":0.07982}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16729","description":"undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the caller setting them. Applications that pass user-controlled input to these fields, such as multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, or the Secure, HttpOnly, and SameSite attributes forced, stripped, or overridden. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0."}]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59997"},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59997"},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59997"},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59997"},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59997"},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59997"},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59997"},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"de286a9b7e19b2a8","cpes":["cpe:2.3:a:stream-json:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream-json:stream_json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream_json:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream_json:stream_json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream:stream_json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:uhop:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:uhop:stream_json:1.9.1:*:*:*:*:*:*:*"],"name":"stream-json","purl":"pkg:npm/stream-json@1.9.1","type":"npm","version":"1.9.1","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/stream-json@1.9.1/node_modules/stream-json/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/stream-json@1.9.1/node_modules/stream-json/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-528h-pc64-c93x","versionConstraint":"<=3.4.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"stream-json","version":"1.9.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-528h-pc64-c93x","fix":{"state":"fixed","versions":["3.5.0"],"available":[{"date":"2026-09-04","kind":"first-observed","version":"3.5.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71429","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71429","date":"2026-10-08","epss":0.0016,"percentile":0.04646}],"risk":0.08960000000000001,"urls":["https://github.com/uhop/stream-json/security/advisories/GHSA-528h-pc64-c93x","https://github.com/uhop/stream-json/commit/a869fb98aaef9225556f49901a8f55954ff856e6"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-528h-pc64-c93x","description":"stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-71429","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71429","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71429","date":"2026-10-08","epss":0.0016,"percentile":0.04646}],"urls":["https://github.com/uhop/stream-json/commit/a869fb98aaef9225556f49901a8f55954ff856e6","https://github.com/uhop/stream-json/security/advisories/GHSA-528h-pc64-c93x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-71429","description":"stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, filter, and replace in src/core/filters/filter-base.js recompute the full path string from the nesting stack for every checkable token. Because the stack length equals the current nesting depth and a checkable token is emitted at every level, a depth D document costs O(D²) rather than O(D) to process. The issue is triggered by nesting depth rather than byte volume, including the documented pick({filter: 'data'}) traversal-until-match path, so an application that sends untrusted JSON through a string or RegExp filter can block the Node.js event loop and cause denial of service with a small deeply nested document. The streamArray, streamObject, and streamValues streamers are not affected because they use the constant-time asm.depth getter. This issue is fixed in version 3.5.0."}]},{"artifact":{"id":"d601a8f22159af10","cpes":["cpe:2.3:a:nodejs:undici:6.27.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.27.0","type":"npm","version":"6.27.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m8rv-5g2x-5cg5","versionConstraint":"<6.28.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.27.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-m8rv-5g2x-5cg5","fix":{"state":"fixed","versions":["6.28.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"6.28.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15157","cwe":"CWE-93","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-15157","date":"2026-10-08","epss":0.00193,"percentile":0.08179}],"risk":0.08878000000000001,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5","https://nvd.nist.gov/vuln/detail/CVE-2026-15157","https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d","https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400","https://github.com/nodejs/undici/commit/7d3cf924c262c486bc77f951348f4e5c847b7b42","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.0","https://github.com/nodejs/undici/releases/tag/v7.29.0","https://github.com/nodejs/undici/releases/tag/v8.9.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m8rv-5g2x-5cg5","description":"undici vulnerable to CRLF Injection via blob-like body 'type' property"},"relatedVulnerabilities":[{"id":"CVE-2026-15157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15157","cwe":"CWE-93","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-15157","date":"2026-10-08","epss":0.00193,"percentile":0.08179}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15157","description":"undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0."}]},{"artifact":{"id":"3c2cf04a1811dafc","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54872","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54872","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."},"relatedVulnerabilities":[]},{"artifact":{"id":"d601a8f22159af10","cpes":["cpe:2.3:a:nodejs:undici:6.27.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.27.0","type":"npm","version":"6.27.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8xcm-r25x-g524","versionConstraint":"<6.28.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.27.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-8xcm-r25x-g524","fix":{"state":"fixed","versions":["6.28.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"6.28.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16728","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-16728","date":"2026-10-08","epss":0.00176,"percentile":0.06563}],"risk":0.08624,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524","https://nvd.nist.gov/vuln/detail/CVE-2026-16728","https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c","https://github.com/nodejs/undici/commit/2b3f749336d356bbbc50192f87f6cf7bc714721a","https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7","https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420","https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e","https://github.com/nodejs/undici/commit/e11a68ed4ff345c79402476f7a00d473443e318d","https://hackerone.com/reports/3828685","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.0","https://github.com/nodejs/undici/releases/tag/v7.29.0","https://github.com/nodejs/undici/releases/tag/v8.9.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8xcm-r25x-g524","description":"undici vulnerable to downstream response desynchronization via retry interceptor"},"relatedVulnerabilities":[{"id":"CVE-2026-16728","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16728","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-16728","date":"2026-10-08","epss":0.00176,"percentile":0.06563}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16728","description":"undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a malicious or faulty upstream can return a partial response with a mismatched framing header, close the socket early, and have the retry interceptor assemble a body of a different length while the original Content-Length stays attached. Applications that use the retry interceptor and forward upstream headers and bodies downstream, such as proxies or gateways, may then emit an invalid HTTP response with a stale Content-Length, leading to downstream response desynchronization, connection hangs, or response corruption. Exploitation requires the retry interceptor enabled, an upstream returning a mismatched partial response, and a downstream forwarder that does not remove or recalculate Content-Length. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0."}]},{"artifact":{"id":"8092b16b55387366","cpes":["cpe:2.3:a:grpc:grpc:1.14.4:*:*:*:*:node.js:*:*"],"name":"@grpc/grpc-js","purl":"pkg:npm/%40grpc/grpc-js@1.14.4","type":"npm","version":"1.14.4","language":"javascript","licenses":["Apache-2.0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@grpc+grpc-js@1.14.4/node_modules/@grpc/grpc-js/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@grpc+grpc-js@1.14.4/node_modules/@grpc/grpc-js/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.14.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f596-whhp-79r4","versionConstraint":">=1.14.0,<1.14.5 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@grpc/grpc-js","version":"1.14.4"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-f596-whhp-79r4","fix":{"state":"fixed","versions":["1.14.5"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.14.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101915","cwe":"CWE-550","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101915","date":"2026-10-08","epss":0.00251,"percentile":0.15054}],"risk":0.084085,"urls":["https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4","https://nvd.nist.gov/vuln/detail/CVE-2026-101915","https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea","https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f","https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d","https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6","https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5"],"severity":"Low","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f596-whhp-79r4","description":"@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages"},"relatedVulnerabilities":[{"id":"CVE-2026-101915","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101915","cwe":"CWE-550","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101915","date":"2026-10-08","epss":0.00251,"percentile":0.15054}],"urls":["https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea","https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f","https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d","https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6","https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5","https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101915","description":"@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status message sent to the client. The thrown error message is transmitted to the client, causing sensitive information disclosure when the message contains sensitive data. This issue is fixed in versions 1.13.6 and 1.14.5."}]},{"artifact":{"id":"3c2cf04a1811dafc","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"419bb9cfaac3bb02","cpes":["cpe:2.3:a:libexpat:libexpat:2.8.3-r1:*:*:*:*:*:*:*"],"name":"libexpat","purl":"pkg:apk/alpine/libexpat@2.8.3-r1?arch=x86_64&distro=alpine-3.24&upstream=expat","type":"apk","version":"2.8.3-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libexpat.so.1"},{"path":"/usr/lib/libexpat.so.1.12.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"expat"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.8.4-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76957","versionConstraint":"< 2.8.4-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"expat","version":"2.8.3-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-76957","fix":{"state":"fixed","versions":["2.8.4-r0"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"2.8.4-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76957","date":"2026-10-08","epss":0.00107,"percentile":0.01051}],"risk":0.081855,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-76957"},"relatedVulnerabilities":[{"id":"CVE-2026-76957","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76957","date":"2026-10-08","epss":0.00107,"percentile":0.01051}],"urls":["https://github.com/libexpat/libexpat/pull/1322","https://github.com/libexpat/libexpat/pull/1329"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76957","description":"libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412."}]},{"artifact":{"id":"b10dc1a504eb1ab3","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-77696","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."},"relatedVulnerabilities":[]},{"artifact":{"id":"a35bb6c2fc3d1cd9","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r1?arch=x86_64&distro=alpine-3.24&upstream=openssl","type":"apk","version":"3.5.7-r1","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-77696","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."},"relatedVulnerabilities":[]},{"artifact":{"id":"d601a8f22159af10","cpes":["cpe:2.3:a:nodejs:undici:6.27.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.27.0","type":"npm","version":"6.27.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:aa0190d3b2af7222bbe9acf0c40a1cd80c2b587f7358195b6dea9deef9f2fb75","accessPath":"/usr/local/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r53p-7pc4-xj5r","versionConstraint":"<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.27.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-r53p-7pc4-xj5r","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18540","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-18540","date":"2026-10-08","epss":0.00239,"percentile":0.13769}],"risk":0.080065,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r","https://nvd.nist.gov/vuln/detail/CVE-2026-18540","https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329","https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95","https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548","https://hackerone.com/reports/3900104","https://hackerone.com/reports/3900615","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"Low","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r53p-7pc4-xj5r","description":"undici vulnerable to downstream response splitting via retry interceptor"},"relatedVulnerabilities":[{"id":"CVE-2026-18540","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18540","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-18540","date":"2026-10-08","epss":0.00239,"percentile":0.13769}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18540","description":"undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"fae15e6d4c5e7e92","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/undici@6.28.0/node_modules/undici/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/undici@6.28.0/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r53p-7pc4-xj5r","versionConstraint":"<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-r53p-7pc4-xj5r","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18540","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-18540","date":"2026-10-08","epss":0.00239,"percentile":0.13769}],"risk":0.080065,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r","https://nvd.nist.gov/vuln/detail/CVE-2026-18540","https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329","https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95","https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548","https://hackerone.com/reports/3900104","https://hackerone.com/reports/3900615","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"Low","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r53p-7pc4-xj5r","description":"undici vulnerable to downstream response splitting via retry interceptor"},"relatedVulnerabilities":[{"id":"CVE-2026-18540","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18540","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-18540","date":"2026-10-08","epss":0.00239,"percentile":0.13769}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18540","description":"undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"1b9771ed454c8ce9","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:6c9348c00ade4fb0d7f642faab3b8c654a86c3ee182fe1e7e021ca5eb05151c9","accessPath":"/usr/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r53p-7pc4-xj5r","versionConstraint":"<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-r53p-7pc4-xj5r","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18540","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-18540","date":"2026-10-08","epss":0.00239,"percentile":0.13769}],"risk":0.080065,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r","https://nvd.nist.gov/vuln/detail/CVE-2026-18540","https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329","https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95","https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548","https://hackerone.com/reports/3900104","https://hackerone.com/reports/3900615","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"Low","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r53p-7pc4-xj5r","description":"undici vulnerable to downstream response splitting via retry interceptor"},"relatedVulnerabilities":[{"id":"CVE-2026-18540","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18540","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-18540","date":"2026-10-08","epss":0.00239,"percentile":0.13769}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18540","description":"undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73282","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"risk":0.07987,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73282"},"relatedVulnerabilities":[{"id":"CVE-2026-73282","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73282","description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73282","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"risk":0.07987,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73282"},"relatedVulnerabilities":[{"id":"CVE-2026-73282","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73282","description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73282","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"risk":0.07987,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73282"},"relatedVulnerabilities":[{"id":"CVE-2026-73282","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73282","description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73282","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"risk":0.07987,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73282"},"relatedVulnerabilities":[{"id":"CVE-2026-73282","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73282","description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73282","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"risk":0.07987,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73282"},"relatedVulnerabilities":[{"id":"CVE-2026-73282","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73282","description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73282","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"risk":0.07987,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73282"},"relatedVulnerabilities":[{"id":"CVE-2026-73282","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73282","description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73282","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"risk":0.07987,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73282"},"relatedVulnerabilities":[{"id":"CVE-2026-73282","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73282","description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent."}]},{"artifact":{"id":"de286a9b7e19b2a8","cpes":["cpe:2.3:a:stream-json:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream-json:stream_json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream_json:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream_json:stream_json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:stream:stream_json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:uhop:stream-json:1.9.1:*:*:*:*:*:*:*","cpe:2.3:a:uhop:stream_json:1.9.1:*:*:*:*:*:*:*"],"name":"stream-json","purl":"pkg:npm/stream-json@1.9.1","type":"npm","version":"1.9.1","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/stream-json@1.9.1/node_modules/stream-json/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/stream-json@1.9.1/node_modules/stream-json/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hqr4-qq8f-hg3x","versionConstraint":"<=3.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"stream-json","version":"1.9.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-hqr4-qq8f-hg3x","fix":{"state":"fixed","versions":["3.6.0"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"3.6.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104182","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104182","date":"2026-10-08","epss":0.00138,"percentile":0.02773}],"risk":0.07728,"urls":["https://github.com/uhop/stream-json/security/advisories/GHSA-hqr4-qq8f-hg3x","https://nvd.nist.gov/vuln/detail/CVE-2026-104182","https://github.com/uhop/stream-json/commit/c0299dc168ce9455ef5ca5b6a0f6850ee7fa0468","https://github.com/uhop/stream-json/releases/tag/3.6.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hqr4-qq8f-hg3x","description":"stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk"},"relatedVulnerabilities":[{"id":"CVE-2026-104182","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104182","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104182","date":"2026-10-08","epss":0.00138,"percentile":0.02773}],"urls":["https://github.com/uhop/stream-json/commit/c0299dc168ce9455ef5ca5b6a0f6850ee7fa0468","https://github.com/uhop/stream-json/releases/tag/3.6.0","https://github.com/uhop/stream-json/security/advisories/GHSA-hqr4-qq8f-hg3x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104182","description":"stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0."}]},{"artifact":{"id":"ea76f17754cba393","cpes":["cpe:2.3:a:\\@langchain\\/redis:\\@langchain\\/redis:1.0.1:*:*:*:*:*:*:*","cpe:2.3:a:langchain-ai:\\@langchain\\/redis:1.0.1:*:*:*:*:*:*:*"],"name":"@langchain/redis","purl":"pkg:npm/%40langchain/redis@1.0.1","type":"npm","version":"1.0.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@langchain+redis@1.0.1_@langchain+core@1.2.8_@opentelemetry+api@1.9.1_@opentelemetry+ex_74acf5db78bff69c6f1e7d995147ae6c/node_modules/@langchain/redis/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@langchain+redis@1.0.1_@langchain+core@1.2.8_@opentelemetry+api@1.9.1_@opentelemetry+ex_74acf5db78bff69c6f1e7d995147ae6c/node_modules/@langchain/redis/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5x6v-p487-7qh2","versionConstraint":"<=1.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@langchain/redis","version":"1.0.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-5x6v-p487-7qh2","fix":{"state":"fixed","versions":["1.1.1"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.1.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105799","cwe":"CWE-943","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-105799","date":"2026-10-08","epss":0.00278,"percentile":0.18595}],"risk":0.07367,"urls":["https://github.com/langchain-ai/langchainjs/security/advisories/GHSA-5x6v-p487-7qh2","https://nvd.nist.gov/vuln/detail/CVE-2026-105799","https://github.com/langchain-ai/langchainjs/pull/10701","https://github.com/langchain-ai/langchainjs/commit/880e3969ea643a2147777a4d5e8bd606a697edf7","https://github.com/langchain-ai/langchainjs/releases/tag/@langchain/redis@1.1.1"],"severity":"Low","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5x6v-p487-7qh2","description":"LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values"},"relatedVulnerabilities":[{"id":"CVE-2026-105799","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105799","cwe":"CWE-943","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-105799","date":"2026-10-08","epss":0.00278,"percentile":0.18595}],"urls":["https://github.com/langchain-ai/langchainjs/commit/880e3969ea643a2147777a4d5e8bd606a697edf7","https://github.com/langchain-ai/langchainjs/pull/10701","https://github.com/langchain-ai/langchainjs/releases/tag/@langchain/redis@1.1.1","https://github.com/langchain-ai/langchainjs/security/advisories/GHSA-5x6v-p487-7qh2"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105799","description":"LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1."}]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73281","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"risk":0.05134999999999999,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73281"},"relatedVulnerabilities":[{"id":"CVE-2026-73281","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73281","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"risk":0.05134999999999999,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73281"},"relatedVulnerabilities":[{"id":"CVE-2026-73281","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73281","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"risk":0.05134999999999999,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73281"},"relatedVulnerabilities":[{"id":"CVE-2026-73281","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73281","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"risk":0.05134999999999999,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73281"},"relatedVulnerabilities":[{"id":"CVE-2026-73281","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73281","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"risk":0.05134999999999999,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73281"},"relatedVulnerabilities":[{"id":"CVE-2026-73281","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73281","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"risk":0.05134999999999999,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73281"},"relatedVulnerabilities":[{"id":"CVE-2026-73281","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73281","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"risk":0.05134999999999999,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73281"},"relatedVulnerabilities":[{"id":"CVE-2026-73281","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension."}]},{"artifact":{"id":"afa69f01b5a5aaac","cpes":["cpe:2.3:a:pcre2:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.47-r1:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.47-r1:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.47-r1?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.47-r1","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.15.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.7"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.48-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"< 10.48-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"pcre2","version":"10.47-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"fixed","versions":["10.48-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"10.48-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.04913999999999999,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"f164a8f6e5d5b275","cpes":["cpe:2.3:a:openssh:openssh:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh","purl":"pkg:apk/alpine/openssh@10.3_p1-r0?arch=x86_64&distro=alpine-3.24","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/ssh-pkcs11-helper"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-73283","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73283","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73283","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"risk":0.025025000000000006,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73283"},"relatedVulnerabilities":[{"id":"CVE-2026-73283","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73283","description":"In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not."}]},{"artifact":{"id":"cc7e7edbd8c56a65","cpes":["cpe:2.3:a:openssh-client-common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_common:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-common","purl":"pkg:apk/alpine/openssh-client-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/moduli"},{"path":"/etc/ssh/ssh_config"},{"path":"/etc/ssh/ssh_config.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/findssl.sh"},{"path":"/usr/bin/scp"},{"path":"/usr/bin/sftp"},{"path":"/usr/bin/ssh-add"},{"path":"/usr/bin/ssh-agent"},{"path":"/usr/bin/ssh-copy-id"},{"path":"/usr/bin/ssh-keyscan"},{"path":"/usr/bin/ssh-pkcs11-helper"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/var"},{"path":"/var/empty"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73283","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73283","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"risk":0.025025000000000006,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73283"},"relatedVulnerabilities":[{"id":"CVE-2026-73283","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73283","description":"In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not."}]},{"artifact":{"id":"76b5d3c989aef8a2","cpes":["cpe:2.3:a:openssh-client-default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client-default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client_default:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client-default:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client_default:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-client-default","purl":"pkg:apk/alpine/openssh-client-default@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73283","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73283","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"risk":0.025025000000000006,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73283"},"relatedVulnerabilities":[{"id":"CVE-2026-73283","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73283","description":"In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not."}]},{"artifact":{"id":"60dddf6a0ed8a8cf","cpes":["cpe:2.3:a:openssh-keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_keygen:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-keygen:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_keygen:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-keygen","purl":"pkg:apk/alpine/openssh-keygen@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssh-keygen"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73283","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73283","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"risk":0.025025000000000006,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73283"},"relatedVulnerabilities":[{"id":"CVE-2026-73283","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73283","description":"In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not."}]},{"artifact":{"id":"f558bb6d9ffd9621","cpes":["cpe:2.3:a:openssh-server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server","purl":"pkg:apk/alpine/openssh-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sshd-auth"},{"path":"/usr/lib/ssh/sshd-session"},{"path":"/usr/sbin"},{"path":"/usr/sbin/sshd"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73283","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73283","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"risk":0.025025000000000006,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73283"},"relatedVulnerabilities":[{"id":"CVE-2026-73283","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73283","description":"In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not."}]},{"artifact":{"id":"126360f8107ce265","cpes":["cpe:2.3:a:openssh-server-common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server-common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server_common:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_server:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-server-common:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_server_common:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-server-common","purl":"pkg:apk/alpine/openssh-server-common@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssh"},{"path":"/etc/ssh/sshd_config"},{"path":"/etc/ssh/sshd_config.d"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73283","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73283","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"risk":0.025025000000000006,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73283"},"relatedVulnerabilities":[{"id":"CVE-2026-73283","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73283","description":"In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not."}]},{"artifact":{"id":"5fb99b683b8ee4d3","cpes":["cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp-server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp_server:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh-sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh_sftp:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-sftp-server:10.3_p1-r0:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_sftp_server:10.3_p1-r0:*:*:*:*:*:*:*"],"name":"openssh-sftp-server","purl":"pkg:apk/alpine/openssh-sftp-server@10.3_p1-r0?arch=x86_64&distro=alpine-3.24&upstream=openssh","type":"apk","version":"10.3_p1-r0","language":"","licenses":["SSH-OpenSSH"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ssh"},{"path":"/usr/lib/ssh/sftp-server"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.3_p1-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73283","versionConstraint":"< 10.3_p1-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"openssh","version":"10.3_p1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73283","fix":{"state":"fixed","versions":["10.3_p1-r1"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"10.3_p1-r1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"risk":0.025025000000000006,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73283"},"relatedVulnerabilities":[{"id":"CVE-2026-73283","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73283","date":"2026-10-08","epss":0.00091,"percentile":0.00452}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73283","description":"In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not."}]},{"artifact":{"id":"498c0969a2581ef0","cpes":["cpe:2.3:a:\\@tiptap\\/core:\\@tiptap\\/core:3.27.0:*:*:*:*:*:*:*","cpe:2.3:a:ueberdosis:\\@tiptap\\/core:3.27.0:*:*:*:*:*:*:*"],"name":"@tiptap/core","purl":"pkg:npm/%40tiptap/core@3.27.0","type":"npm","version":"3.27.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@tiptap+core@3.27.0_@tiptap+pm@3.27.0/node_modules/@tiptap/core/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@tiptap+core@3.27.0_@tiptap+pm@3.27.0/node_modules/@tiptap/core/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.30.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j95f-988m-3j2f","versionConstraint":">=3.7.0,<3.30.5 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@tiptap/core","version":"3.27.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j95f-988m-3j2f","fix":{"state":"fixed","versions":["3.30.5"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"3.30.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/ueberdosis/tiptap/security/advisories/GHSA-j95f-988m-3j2f","https://github.com/ueberdosis/tiptap/commit/d0d499be3cce633cf54ca9aa9f3d8a5a1f98bd74","https://github.com/ueberdosis/tiptap/releases/tag/v3.30.5"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j95f-988m-3j2f","description":"Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing"},"relatedVulnerabilities":[]},{"artifact":{"id":"1f2b146f1ddb7f99","cpes":["cpe:2.3:a:\\@vue\\/server-renderer:\\@vue\\/server-renderer:3.5.40:*:*:*:*:*:*:*","cpe:2.3:a:\\@vue\\/server-renderer:\\@vue\\/server_renderer:3.5.40:*:*:*:*:*:*:*","cpe:2.3:a:\\@vue\\/server_renderer:\\@vue\\/server-renderer:3.5.40:*:*:*:*:*:*:*","cpe:2.3:a:\\@vue\\/server_renderer:\\@vue\\/server_renderer:3.5.40:*:*:*:*:*:*:*","cpe:2.3:a:\\@vue\\/server:\\@vue\\/server-renderer:3.5.40:*:*:*:*:*:*:*","cpe:2.3:a:\\@vue\\/server:\\@vue\\/server_renderer:3.5.40:*:*:*:*:*:*:*","cpe:2.3:a:vuejs:\\@vue\\/server-renderer:3.5.40:*:*:*:*:*:*:*","cpe:2.3:a:vuejs:\\@vue\\/server_renderer:3.5.40:*:*:*:*:*:*:*"],"name":"@vue/server-renderer","purl":"pkg:npm/%40vue/server-renderer@3.5.40","type":"npm","version":"3.5.40","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@vue+server-renderer@3.5.40/node_modules/@vue/server-renderer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@vue+server-renderer@3.5.40/node_modules/@vue/server-renderer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.42"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g2v6-rqmx-r4w6","versionConstraint":"<3.5.42 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@vue/server-renderer","version":"3.5.40"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-g2v6-rqmx-r4w6","fix":{"state":"fixed","versions":["3.5.42"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"3.5.42"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/vuejs/core/security/advisories/GHSA-g2v6-rqmx-r4w6","https://github.com/vuejs/core/pull/15266","https://github.com/vuejs/core/commit/a2b40db9a83b36ed9da3a16403cf8f040262d73f","https://github.com/vuejs/core/releases/tag/v3.5.42","https://github.com/vuejs/core/releases/tag/v3.6.0-rc.6"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g2v6-rqmx-r4w6","description":"@vue/server-renderer: XSS via missing CR in attribute-name blacklist"},"relatedVulnerabilities":[]},{"artifact":{"id":"31a0e0e0d1265f89","cpes":["cpe:2.3:a:adm-zip_project:adm-zip:0.6.0:*:*:*:*:node.js:*:*"],"name":"adm-zip","purl":"pkg:npm/adm-zip@0.6.0","type":"npm","version":"0.6.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8238-w5pm-2374","versionConstraint":"<=0.6.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"adm-zip","version":"0.6.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-8238-w5pm-2374","fix":{"state":"fixed","versions":["0.6.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"0.6.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/cthackers/adm-zip/security/advisories/GHSA-8238-w5pm-2374","https://github.com/cthackers/adm-zip/commit/5e70d3a26097d68fa981c41f022c053117174e49","https://github.com/cthackers/adm-zip/releases/tag/v0.6.1"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8238-w5pm-2374","description":"adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)"},"relatedVulnerabilities":[]},{"artifact":{"id":"31a0e0e0d1265f89","cpes":["cpe:2.3:a:adm-zip_project:adm-zip:0.6.0:*:*:*:*:node.js:*:*"],"name":"adm-zip","purl":"pkg:npm/adm-zip@0.6.0","type":"npm","version":"0.6.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rcw4-f5rp-g42v","versionConstraint":"<=0.6.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"adm-zip","version":"0.6.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rcw4-f5rp-g42v","fix":{"state":"fixed","versions":["0.6.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"0.6.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/cthackers/adm-zip/security/advisories/GHSA-rcw4-f5rp-g42v","https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6","https://github.com/cthackers/adm-zip/releases/tag/v0.6.1"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rcw4-f5rp-g42v","description":"adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0"},"relatedVulnerabilities":[]},{"artifact":{"id":"631511184b49ac5d","cpes":["cpe:2.3:a:nodemailer:nodemailer:8.0.10:*:*:*:*:node.js:*:*"],"name":"nodemailer","purl":"pkg:npm/nodemailer@8.0.10","type":"npm","version":"8.0.10","language":"javascript","licenses":["MIT-0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"9.1.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2x7j-588g-ccc2","versionConstraint":"<9.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"nodemailer","version":"8.0.10"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-2x7j-588g-ccc2","fix":{"state":"fixed","versions":["9.1.0"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"9.1.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2","https://github.com/nodemailer/nodemailer/pull/1848","https://github.com/nodemailer/nodemailer/commit/34da64282dcdc9b0581c721a27ab2fa226673150","https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e","https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434","https://github.com/nodemailer/nodemailer/releases/tag/v9.1.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2x7j-588g-ccc2","description":"Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list"},"relatedVulnerabilities":[]},{"artifact":{"id":"631511184b49ac5d","cpes":["cpe:2.3:a:nodemailer:nodemailer:8.0.10:*:*:*:*:node.js:*:*"],"name":"nodemailer","purl":"pkg:npm/nodemailer@8.0.10","type":"npm","version":"8.0.10","language":"javascript","licenses":["MIT-0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.0.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v53p-9fqp-m79j","versionConstraint":"<=10.0.5 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"nodemailer","version":"8.0.10"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-v53p-9fqp-m79j","fix":{"state":"fixed","versions":["10.0.6"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.0.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j","https://github.com/nodemailer/nodemailer/commit/437d7fc47403df176bc39271641541b7a9bce102","https://github.com/nodemailer/nodemailer/releases/tag/v10.0.6"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v53p-9fqp-m79j","description":"Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service"},"relatedVulnerabilities":[]},{"artifact":{"id":"498c0969a2581ef0","cpes":["cpe:2.3:a:\\@tiptap\\/core:\\@tiptap\\/core:3.27.0:*:*:*:*:*:*:*","cpe:2.3:a:ueberdosis:\\@tiptap\\/core:3.27.0:*:*:*:*:*:*:*"],"name":"@tiptap/core","purl":"pkg:npm/%40tiptap/core@3.27.0","type":"npm","version":"3.27.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@tiptap+core@3.27.0_@tiptap+pm@3.27.0/node_modules/@tiptap/core/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/@tiptap+core@3.27.0_@tiptap+pm@3.27.0/node_modules/@tiptap/core/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.30.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cp6q-959q-f8rh","versionConstraint":">=2.0.0-alpha.0,<3.30.4 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@tiptap/core","version":"3.27.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-cp6q-959q-f8rh","fix":{"state":"fixed","versions":["3.30.4"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"3.30.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N","metrics":{"baseScore":6.4},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/ueberdosis/tiptap/security/advisories/GHSA-cp6q-959q-f8rh","https://github.com/ueberdosis/tiptap/commit/01d7af8c983ee5954c63734f4fa46cb23ae3246d","https://github.com/ueberdosis/tiptap/releases/tag/v3.30.4"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cp6q-959q-f8rh","description":"Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes"},"relatedVulnerabilities":[]},{"artifact":{"id":"31a0e0e0d1265f89","cpes":["cpe:2.3:a:adm-zip_project:adm-zip:0.6.0:*:*:*:*:node.js:*:*"],"name":"adm-zip","purl":"pkg:npm/adm-zip@0.6.0","type":"npm","version":"0.6.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c6fg-446q-cg94","versionConstraint":"<=0.6.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"adm-zip","version":"0.6.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-c6fg-446q-cg94","fix":{"state":"fixed","versions":["0.6.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"0.6.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/cthackers/adm-zip/security/advisories/GHSA-c6fg-446q-cg94","https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6","https://github.com/cthackers/adm-zip/releases/tag/v0.6.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c6fg-446q-cg94","description":"adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path"},"relatedVulnerabilities":[]},{"artifact":{"id":"31a0e0e0d1265f89","cpes":["cpe:2.3:a:adm-zip_project:adm-zip:0.6.0:*:*:*:*:node.js:*:*"],"name":"adm-zip","purl":"pkg:npm/adm-zip@0.6.0","type":"npm","version":"0.6.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/adm-zip@0.6.0/node_modules/adm-zip/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p634-w6r4-rjp2","versionConstraint":"<=0.6.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"adm-zip","version":"0.6.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-p634-w6r4-rjp2","fix":{"state":"fixed","versions":["0.6.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"0.6.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/cthackers/adm-zip/security/advisories/GHSA-p634-w6r4-rjp2","https://github.com/cthackers/adm-zip/commit/05101d47b3b983b705cc3e66fc34366118ba7b99","https://github.com/cthackers/adm-zip/releases/tag/v0.6.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p634-w6r4-rjp2","description":"adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content"},"relatedVulnerabilities":[]},{"artifact":{"id":"cc24196b56ba8cc2","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_418ebec8ee03118a5a8498785d25104f/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-44g4-m2mj-wpvx","versionConstraint":">=1.15.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-44g4-m2mj-wpvx","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/axios/axios/security/advisories/GHSA-44g4-m2mj-wpvx","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-44g4-m2mj-wpvx","description":"Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges"},"relatedVulnerabilities":[{"id":"CVE-2026-101899","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"e3dd74d996d006f9","cpes":["cpe:2.3:a:axios:axios:1.18.0:*:*:*:*:node.js:*:*"],"name":"axios","purl":"pkg:npm/axios@1.18.0","type":"npm","version":"1.18.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/axios@1.18.0_patch_hash=149e256a2a7b632497650b32816716ced972ab02a5ab00fbd8a5158a51722c4_437e4fafb503be805d1d0ae72f0b0deb/node_modules/axios/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-44g4-m2mj-wpvx","versionConstraint":">=1.15.0,<1.20.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"axios","version":"1.18.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-44g4-m2mj-wpvx","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.20.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/axios/axios/security/advisories/GHSA-44g4-m2mj-wpvx","https://github.com/axios/axios/pull/11141","https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","https://github.com/axios/axios/releases/tag/v1.20.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-44g4-m2mj-wpvx","description":"Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges"},"relatedVulnerabilities":[{"id":"CVE-2026-101899","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"3b8f27c62542446d","cpes":["cpe:2.3:a:markdown-it_project:markdown-it:13.0.2:*:*:*:*:*:*:*"],"name":"markdown-it","purl":"pkg:npm/markdown-it@13.0.2","type":"npm","version":"13.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/markdown-it@13.0.2/node_modules/markdown-it/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/markdown-it@13.0.2/node_modules/markdown-it/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"14.3.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-253c-mchw-3w2r","versionConstraint":"<14.3.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"markdown-it","version":"13.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-253c-mchw-3w2r","fix":{"state":"fixed","versions":["14.3.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"14.3.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/markdown-it/markdown-it/security/advisories/GHSA-253c-mchw-3w2r","https://github.com/markdown-it/markdown-it/commit/09fa07118dda4c953f058848f53dae88395618ca","https://github.com/markdown-it/markdown-it/commit/aaadcfa6d817b3c5f89afb49d97c7b797a6dd4fd","https://github.com/markdown-it/markdown-it/commit/ad70f6b7cff64bee10e42a774147112480ca0d49"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-253c-mchw-3w2r","description":"markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of seconds"},"relatedVulnerabilities":[]},{"artifact":{"id":"631511184b49ac5d","cpes":["cpe:2.3:a:nodemailer:nodemailer:8.0.10:*:*:*:*:node.js:*:*"],"name":"nodemailer","purl":"pkg:npm/nodemailer@8.0.10","type":"npm","version":"8.0.10","language":"javascript","licenses":["MIT-0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6vj9-mwq6-2f5v","versionConstraint":">=5.0.0,<10.0.2 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"nodemailer","version":"8.0.10"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6vj9-mwq6-2f5v","fix":{"state":"fixed","versions":["10.0.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.0.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/nodemailer/nodemailer/security/advisories/GHSA-6vj9-mwq6-2f5v","https://github.com/nodemailer/nodemailer/commit/a6512dbcb3c6e7f2f70d3acccc5752defe3c61fe","https://github.com/nodemailer/nodemailer/releases/tag/v10.0.2"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6vj9-mwq6-2f5v","description":"Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure"},"relatedVulnerabilities":[]},{"artifact":{"id":"631511184b49ac5d","cpes":["cpe:2.3:a:nodemailer:nodemailer:8.0.10:*:*:*:*:node.js:*:*"],"name":"nodemailer","purl":"pkg:npm/nodemailer@8.0.10","type":"npm","version":"8.0.10","language":"javascript","licenses":["MIT-0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"9.1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8m3c-c648-2xjj","versionConstraint":"<=9.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"nodemailer","version":"8.0.10"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-8m3c-c648-2xjj","fix":{"state":"fixed","versions":["9.1.1"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"9.1.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8m3c-c648-2xjj","https://github.com/nodemailer/nodemailer/commit/ab7ef348b9a97b1fd70e7bfbeb56d4ea4a07946b","https://github.com/nodemailer/nodemailer/commit/dc48ed395c4d6c79ee5c95eb6eff17bafe391474","https://github.com/nodemailer/nodemailer/releases/tag/v9.1.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8m3c-c648-2xjj","description":"Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature"},"relatedVulnerabilities":[]},{"artifact":{"id":"631511184b49ac5d","cpes":["cpe:2.3:a:nodemailer:nodemailer:8.0.10:*:*:*:*:node.js:*:*"],"name":"nodemailer","purl":"pkg:npm/nodemailer@8.0.10","type":"npm","version":"8.0.10","language":"javascript","licenses":["MIT-0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8vvx-rff5-p5rq","versionConstraint":"<10.0.2 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"nodemailer","version":"8.0.10"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-8vvx-rff5-p5rq","fix":{"state":"fixed","versions":["10.0.2"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.0.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8vvx-rff5-p5rq","https://github.com/nodemailer/nodemailer/commit/ebe084940aef88278afc6016b78c6d1c3821bb66","https://github.com/nodemailer/nodemailer/releases/tag/v10.0.2"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8vvx-rff5-p5rq","description":"Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS"},"relatedVulnerabilities":[]},{"artifact":{"id":"631511184b49ac5d","cpes":["cpe:2.3:a:nodemailer:nodemailer:8.0.10:*:*:*:*:node.js:*:*"],"name":"nodemailer","purl":"pkg:npm/nodemailer@8.0.10","type":"npm","version":"8.0.10","language":"javascript","licenses":["MIT-0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"9.1.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cc9r-2j5m-2m83","versionConstraint":">=6.9.16,<9.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"nodemailer","version":"8.0.10"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-cc9r-2j5m-2m83","fix":{"state":"fixed","versions":["9.1.0"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"9.1.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/nodemailer/nodemailer/security/advisories/GHSA-cc9r-2j5m-2m83","https://github.com/nodemailer/nodemailer/pull/1848","https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880","https://github.com/nodemailer/nodemailer/releases/tag/v9.1.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cc9r-2j5m-2m83","description":"Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain"},"relatedVulnerabilities":[]},{"artifact":{"id":"631511184b49ac5d","cpes":["cpe:2.3:a:nodemailer:nodemailer:8.0.10:*:*:*:*:node.js:*:*"],"name":"nodemailer","purl":"pkg:npm/nodemailer@8.0.10","type":"npm","version":"8.0.10","language":"javascript","licenses":["MIT-0"],"locations":[{"path":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","layerID":"sha256:07d538a793c4d1c6df827dc391460c8598c3f606116cce77885f92be9c87a565","accessPath":"/usr/local/lib/node_modules/n8n/node_modules/.pnpm/nodemailer@8.0.10/node_modules/nodemailer/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"9.1.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmmp-3585-3rmp","versionConstraint":"<9.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"nodemailer","version":"8.0.10"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-wmmp-3585-3rmp","fix":{"state":"fixed","versions":["9.1.0"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"9.1.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wmmp-3585-3rmp","https://github.com/nodemailer/nodemailer/pull/1848","https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148","https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e","https://github.com/nodemailer/nodemailer/releases/tag/v9.1.0"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmmp-3585-3rmp","description":"Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain"},"relatedVulnerabilities":[]},{"artifact":{"id":"70617bfbfe6f615d","cpes":["cpe:2.3:a:libcurl:libcurl:8.21.0-r0:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:apk/alpine/libcurl@8.21.0-r0?arch=x86_64&distro=alpine-3.24&upstream=curl","type":"apk","version":"8.21.0-r0","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcurl.so.4"},{"path":"/usr/lib/libcurl.so.4.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"8.22.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80256","versionConstraint":"< 8.22.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"curl","version":"8.21.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-80256","fix":{"state":"fixed","versions":["8.22.0-r0"],"available":[{"date":"2026-09-03","kind":"first-observed","version":"8.22.0-r0"}]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-80256"},"relatedVulnerabilities":[{"id":"CVE-2026-80256","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"c621e9fea7d51d49","cpes":["cpe:2.3:a:libpng:libpng:1.6.58-r1:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:apk/alpine/libpng@1.6.58-r1?arch=x86_64&distro=alpine-3.24","type":"apk","version":"1.6.58-r1","language":"","licenses":["Libpng"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpng16.so.16"},{"path":"/usr/lib/libpng16.so.16.58.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:ff56b029b178b2cd49f5b02a481ff8407aa814a46183f1880b88a0dc6db2f922","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libpng"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.6.59-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-46675","versionConstraint":"< 1.6.59-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"libpng","version":"1.6.58-r1"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.6.59-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46675","versionConstraint":"< 1.6.59-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24"},"package":{"name":"libpng","version":"1.6.58-r1"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-46675","fix":{"state":"fixed","versions":["1.6.59-r0"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"1.6.59-r0"}]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-46675"},"relatedVulnerabilities":[{"id":"CVE-2026-46675","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T23:03:20.492Z","grype_db_version":"2026-10-09T06:32:32.000Z"}