{"grype_matches":[{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28388","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28388","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"risk":1.1129450000000003,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28388","description":"A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application."},"relatedVulnerabilities":[{"id":"CVE-2026-28388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"urls":["https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e","https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139","https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3","https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8","https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28389","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28389","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"risk":1.0835750000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28389","description":"A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data."},"relatedVulnerabilities":[{"id":"CVE-2026-28389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"urls":["https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-1.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 1:3.5.8-1.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["1:3.5.8-1.el9_8"],"available":[{"date":"2026-09-14","kind":"first-observed","version":"1:3.5.8-1.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.00125,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:67165","link":"https://access.redhat.com/errata/RHSA-2026:67165"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-63076","description":"A flaw was found in OpenSSL. A crafted CMP (Certificate Management Protocol) message can cause an invalid pointer dereference due to a missing type check in the password-based protection verification. A remote, unauthenticated attacker can crash applications acting as a CMP server or client, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-1.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 1:3.5.8-1.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["1:3.5.8-1.el9_8"],"available":[{"date":"2026-09-14","kind":"first-observed","version":"1:3.5.8-1.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"risk":0.9606250000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:67165","link":"https://access.redhat.com/errata/RHSA-2026:67165"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18798","description":"A flaw was found in OpenSSL. A malformed INITIAL packet with an invalid DCID (destination connection ID) can cause the QUIC server to double free the QRX object. This issue leads to memory corruption, causing the termination of the QUIC server process and resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.695765,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7210","description":"A flaw was found in the `python` and `expat` components. Insufficient entropy in the hash-flooding protection mechanism of `xml.parsers.expat` and `xml.etree.ElementTree` allows a remote attacker to craft a malicious XML document. This crafted document can trigger a hash flooding attack, leading to a denial of service (DoS) condition."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.695765,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7210","description":"A flaw was found in the `python` and `expat` components. Insufficient entropy in the hash-flooding protection mechanism of `xml.parsers.expat` and `xml.etree.ElementTree` allows a remote attacker to craft a malicious XML document. This crafted document can trigger a hash flooding attack, leading to a denial of service (DoS) condition."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"1c27b1fc065b3d30","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=rhel-9.8&upstream=python-pip-21.3.1-2.el9_8.src.rpm","type":"rpm","version":"21.3.1-2.el9_8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"21.3.1-2.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3572","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python-pip","version":"21.3.1-2.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2021-3572","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3572","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2021-3572","date":"2026-10-08","epss":0.01829,"percentile":0.78207}],"risk":0.685875,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-3572","description":"A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity."},"relatedVulnerabilities":[{"id":"CVE-2021-3572","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":3.5,"impactScore":2.9,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3572","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2021-3572","date":"2026-10-08","epss":0.01829,"percentile":0.78207}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1962856","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3572","description":"A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1."}]},{"artifact":{"id":"eb6d8b086c6f955f","cpes":["cpe:2.3:a:jline-remote-telnet:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote-telnet:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote_telnet:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote_telnet:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*"],"name":"jline-remote-telnet","purl":"pkg:maven/org.jline/jline-remote-telnet@3.30.4","type":"java-archive","version":"3.30.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/java/kafka/jline-3.30.4.jar:org.jline:jline-remote-telnet","manifestName":"","pomArtifactID":"jline-remote-telnet","archiveDigests":null},"locations":[{"path":"/usr/share/java/kafka/jline-3.30.4.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jline-3.30.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.14"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2r2c-cx56-8933","versionConstraint":"<3.30.14 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-remote-telnet","version":"3.30.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-2r2c-cx56-8933","fix":{"state":"fixed","versions":["3.30.14"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"3.30.14"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56741","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56741","date":"2026-10-08","epss":0.00889,"percentile":0.58096}],"risk":0.66675,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933","https://nvd.nist.gov/vuln/detail/CVE-2026-56741","https://github.com/jline/jline3/pull/2000","https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708","https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e","https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3","https://github.com/jline/jline3/releases/tag/4.0.16","https://github.com/jline/jline3/releases/tag/4.2.1"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2r2c-cx56-8933","description":"JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry"},"relatedVulnerabilities":[{"id":"CVE-2026-56741","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56741","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56741","date":"2026-10-08","epss":0.00889,"percentile":0.58096}],"urls":["https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708","https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e","https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3","https://github.com/jline/jline3/pull/2000","https://github.com/jline/jline3/releases/tag/4.0.16","https://github.com/jline/jline3/releases/tag/4.2.1","https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56741","description":"JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1."}]},{"artifact":{"id":"eb6d8b086c6f955f","cpes":["cpe:2.3:a:jline-remote-telnet:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote-telnet:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote_telnet:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote_telnet:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-remote-telnet:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_remote_telnet:3.30.4:*:*:*:*:*:*:*"],"name":"jline-remote-telnet","purl":"pkg:maven/org.jline/jline-remote-telnet@3.30.4","type":"java-archive","version":"3.30.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/java/kafka/jline-3.30.4.jar:org.jline:jline-remote-telnet","manifestName":"","pomArtifactID":"jline-remote-telnet","archiveDigests":null},"locations":[{"path":"/usr/share/java/kafka/jline-3.30.4.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jline-3.30.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.14"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-47qp-hqvx-6r3f","versionConstraint":"<3.30.14 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-remote-telnet","version":"3.30.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-47qp-hqvx-6r3f","fix":{"state":"fixed","versions":["3.30.14"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"3.30.14"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56740","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56740","date":"2026-10-08","epss":0.00884,"percentile":0.57976}],"risk":0.663,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f","https://nvd.nist.gov/vuln/detail/CVE-2026-56740","https://github.com/jline/jline3/pull/2000","https://github.com/jline/jline3/pull/2001","https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09","https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40","https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b","https://github.com/jline/jline3/releases/tag/4.0.16","https://github.com/jline/jline3/releases/tag/4.2.1","https://github.com/jline/jline3/releases/tag/jline-3.30.14"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-47qp-hqvx-6r3f","description":"JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables"},"relatedVulnerabilities":[{"id":"CVE-2026-56740","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56740","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56740","date":"2026-10-08","epss":0.00884,"percentile":0.57976}],"urls":["https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09","https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40","https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b","https://github.com/jline/jline3/pull/2000","https://github.com/jline/jline3/pull/2001","https://github.com/jline/jline3/releases/tag/4.0.16","https://github.com/jline/jline3/releases/tag/4.2.1","https://github.com/jline/jline3/releases/tag/jline-3.30.14","https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56740","description":"JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-9232","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-9232","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9232","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9232","date":"2026-10-08","epss":0.02001,"percentile":0.80128}],"risk":0.610305,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-9232","description":"A flaw was found in the OpenSSL HTTP client API no_proxy handling. This vulnerability allows an application level denial of service (application crash) via an attacker-controlled IPv6 URL when the no_proxy environment variable is set."},"relatedVulnerabilities":[{"id":"CVE-2025-9232","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9232","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9232","date":"2026-10-08","epss":0.02001,"percentile":0.80128}],"urls":["https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35","https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b","https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3","https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf","https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0","https://openssl-library.org/news/secadv/20250930.txt","http://www.openwall.com/lists/oss-security/2025/09/30/5","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9232","description":"Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-1.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 1:3.5.8-1.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["1:3.5.8-1.el9_8"],"available":[{"date":"2026-09-14","kind":"first-observed","version":"1:3.5.8-1.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.5725,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:67165","link":"https://access.redhat.com/errata/RHSA-2026:67165"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-63072","description":"A flaw was found in OpenSSL. A crafted CMS (Cryptographic Message Syntax) message can cause an 8-byte out-of-bounds heap write when it is decrypted with CMS_decrypt(). This issue occurs because the CMS decryption process incorrectly sizes the key-unwrap output buffer when using the AES-WRAP-PAD unwrap primitive. This can lead to memory corruption, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.5.0-6.el9_8.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"< 0:2.5.0-6.el9_8.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-66046","fix":{"state":"fixed","versions":["0:2.5.0-6.el9_8.5"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"0:2.5.0-6.el9_8.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"risk":0.5565,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:72663","link":"https://access.redhat.com/errata/RHSA-2026:72663"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-66046","description":"A flaw was found in the Expat XML parsing library. A remote, unauthenticated attacker can supply a specially crafted XML document to trigger quadratic algorithmic complexity in the storeAtts() function, causing excessive CPU consumption and a denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-66046","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-1.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 1:3.5.8-1.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["1:3.5.8-1.el9_8"],"available":[{"date":"2026-09-14","kind":"first-observed","version":"1:3.5.8-1.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:67165","link":"https://access.redhat.com/errata/RHSA-2026:67165"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-14456","description":"A flaw was found in OpenSSL. A remote attacker could exploit this by sending a large number of QUIC Initial packets to an OpenSSL QUIC server. This can cause the server to allocate and queue new incoming channels without limit, leading to unbounded memory growth. The excessive memory consumption can result in a Denial of Service (DoS) condition, making the QUIC listener unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-1.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 1:3.5.8-1.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["1:3.5.8-1.el9_8"],"available":[{"date":"2026-09-14","kind":"first-observed","version":"1:3.5.8-1.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"risk":0.5360250000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:67165","link":"https://access.redhat.com/errata/RHSA-2026:67165"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-14457","description":"A flaw was found in OpenSSL. In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, where only the private key (with no certificate) is configured, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted \"signature_algorithms_cert\" TLS extension. This issue results in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0990","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0990","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0990","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0990","date":"2026-10-08","epss":0.00969,"percentile":0.60707}],"risk":0.528105,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0990","description":"A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications."},"relatedVulnerabilities":[{"id":"CVE-2026-0990","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0990","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0990","date":"2026-10-08","epss":0.00969,"percentile":0.60707}],"urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0990","https://bugzilla.redhat.com/show_bug.cgi?id=2429959","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0990","description":"A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-1.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 1:3.5.8-1.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["1:3.5.8-1.el9_8"],"available":[{"date":"2026-09-14","kind":"first-observed","version":"1:3.5.8-1.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"risk":0.5157550000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:67165","link":"https://access.redhat.com/errata/RHSA-2026:67165"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-63073","description":"A flaw was found in OpenSSL. A malicious CMP (Certificate Management Protocol) endpoint can send an unexpected distinguished name (DN) directly as the format string argument to ERR_raise_data(), causing the application to dereference and write to unrelated stack contents. This can lead to a crash in the CMP client, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-41996","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-41996","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"risk":0.481935,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-41996","description":"A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations."},"relatedVulnerabilities":[{"id":"CVE-2024-41996","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"urls":["https://dheatattack.gitlab.io/details/","https://dheatattack.gitlab.io/faq/","https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41996","description":"Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-41409","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-41409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"risk":0.465215,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-41409","description":"A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack."},"relatedVulnerabilities":[{"id":"CVE-2022-41409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"urls":["https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35","https://github.com/PCRE2Project/pcre2/issues/141"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41409","description":"Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-41409","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-41409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"risk":0.465215,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-41409","description":"A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack."},"relatedVulnerabilities":[{"id":"CVE-2022-41409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"urls":["https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35","https://github.com/PCRE2Project/pcre2/issues/141"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41409","description":"Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input."}]},{"artifact":{"id":"ecae56e691f56928","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=rhel-9.8&upstream=ncurses-6.2-12.20210508.el9.src.rpm","type":"rpm","version":"6.2-12.20210508.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.2-12.20210508.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"ncurses","version":"6.2-12.20210508.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.45315,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-50495","description":"A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"b0fd3764b473721b","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=rhel-9.8&upstream=ncurses-6.2-12.20210508.el9.src.rpm","type":"rpm","version":"6.2-12.20210508.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.2-12.20210508.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"ncurses","version":"6.2-12.20210508.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.45315,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-50495","description":"A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7774","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-7774","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7774","date":"2026-10-08","epss":0.00781,"percentile":0.54586}],"risk":0.449075,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7774","description":"A flaw was found in the `tarfile.data_filter` function within the Python `tarfile` module. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive containing malicious link entries, such as symlinks with empty or directory-like names. This bypass allows the attacker to redirect subsequent archive members outside the intended extraction directory, leading to arbitrary file writes on the system where the archive is extracted. The impact of this flaw is limited by the permissions of the extracting process."},"relatedVulnerabilities":[{"id":"CVE-2026-7774","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7774","date":"2026-10-08","epss":0.00781,"percentile":0.54586}],"urls":["https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","https://github.com/python/cpython/issues/149486","https://github.com/python/cpython/pull/149487","https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","http://www.openwall.com/lists/oss-security/2026/06/04/9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7774","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-7774","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7774","date":"2026-10-08","epss":0.00781,"percentile":0.54586}],"risk":0.449075,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7774","description":"A flaw was found in the `tarfile.data_filter` function within the Python `tarfile` module. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive containing malicious link entries, such as symlinks with empty or directory-like names. This bypass allows the attacker to redirect subsequent archive members outside the intended extraction directory, leading to arbitrary file writes on the system where the archive is extracted. The impact of this flaw is limited by the permissions of the extracting process."},"relatedVulnerabilities":[{"id":"CVE-2026-7774","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7774","date":"2026-10-08","epss":0.00781,"percentile":0.54586}],"urls":["https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","https://github.com/python/cpython/issues/149486","https://github.com/python/cpython/pull/149487","https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","http://www.openwall.com/lists/oss-security/2026/06/04/9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process."}]},{"artifact":{"id":"2b82a2f8958cd6a7","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5","type":"java-archive","version":"2.21.5","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"84924990b468233a28214ae2c505a9ec24cd6ea6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.19.0,<2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.21.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.21.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"13e796f547d90a6a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9e2fb91831cce9cb9262909cd76647508949f232","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.22.0,<2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.22.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.22.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77214","description":"A flaw was found in expat. A remote attacker can exploit this vulnerability through repeated parse buffer operations with unvalidated buffer lengths, causing a heap buffer over-read. This issue primarily leads to information disclosure by leaking adjacent heap memory contents, which could assist in bypassing security mitigations such as Address Space Layout Randomization (ASLR), or result in a Denial of Service (DoS) by crashing the application."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-45322","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-45322","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45322","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45322","date":"2026-10-08","epss":0.00965,"percentile":0.60527}],"risk":0.4294250000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-45322","description":"A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2023-45322","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45322","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45322","date":"2026-10-08","epss":0.00965,"percentile":0.60527}],"urls":["http://www.openwall.com/lists/oss-security/2023/10/06/5","https://gitlab.gnome.org/GNOME/libxml2/-/issues/344","https://gitlab.gnome.org/GNOME/libxml2/-/issues/583","https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45322","description":"libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\""}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.41112499999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11972","description":"A flaw was found in the Python `tarfile` module. When processing a specially crafted tar archive opened in 'streaming mode' (mode='r|'), the module does not properly handle the end-of-file (EOF) condition. This can cause the `tarfile` module to enter an infinite loop, leading to a Denial of Service (DoS) for applications processing such archives."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.41112499999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11972","description":"A flaw was found in the Python `tarfile` module. When processing a specially crafted tar archive opened in 'streaming mode' (mode='r|'), the module does not properly handle the end-of-file (EOF) condition. This can cause the `tarfile` module to enter an infinite loop, leading to a Denial of Service (DoS) for applications processing such archives."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"2da81090dc4febb6","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.21.5:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5","type":"java-archive","version":"2.21.5","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-core-2.21.5.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"7ec0c8bf8402fa998f64b2009632d6566a42ceb7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-core-2.21.5.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jackson-core-2.21.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.21.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"f867e06c7176411d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-java-micro/jackson-core-2.22.1.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"da7ffb60088d7e8f37ecdd3b617520971cc7b9bf","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/jackson-core-2.22.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/jackson-core-2.22.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-1.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 1:3.5.8-1.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["1:3.5.8-1.el9_8"],"available":[{"date":"2026-09-14","kind":"first-observed","version":"1:3.5.8-1.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"risk":0.40845,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:67165","link":"https://access.redhat.com/errata/RHSA-2026:67165"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-63075","description":"A flaw was found in OpenSSL. The QUIC protocol implementation retains metadata for ACK-only packets for the lifetime of a connection, leading to excessive memory consumption. This allows a peer to repeatedly send ack-eliciting packets while not acknowledging ACK-only responses to cause memory exhaustion, eventually resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"23e3d9feac1cb13c","cpes":["cpe:2.3:a:libgcc:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.38505000000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-27943","description":"A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"62a2970ccab3dd86","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.38505000000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-27943","description":"A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"2b82a2f8958cd6a7","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5","type":"java-archive","version":"2.21.5","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"84924990b468233a28214ae2c505a9ec24cd6ea6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.19.0,<2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.21.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.21.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"13e796f547d90a6a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9e2fb91831cce9cb9262909cd76647508949f232","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.22.0,<2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.22.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.22.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"1c27b1fc065b3d30","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=rhel-9.8&upstream=python-pip-21.3.1-2.el9_8.src.rpm","type":"rpm","version":"21.3.1-2.el9_8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"21.3.1-2.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32284","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python-pip","version":"21.3.1-2.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-32284","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32284","date":"2026-10-08","epss":0.00695,"percentile":0.51498}],"risk":0.378775,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-32284","description":"A flaw was found in the msgpack decoder. A remote attacker could send specially crafted, truncated fixext data to an application using the msgpack library. This improper input validation can lead to an out-of-bounds read and a runtime panic, resulting in a denial of service (DoS) attack against the application."},"relatedVulnerabilities":[{"id":"CVE-2026-32284","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32284","date":"2026-10-08","epss":0.00695,"percentile":0.51498}],"urls":["https://github.com/golang/vulndb/issues/4513","https://github.com/shamaton/msgpack/issues/59","https://pkg.go.dev/vuln/GO-2026-4513","https://securityinfinity.com/research/shamaton-msgpack-oob-panic-fixext-dos-2026"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32284","description":"The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4224","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4224","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4224","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4224","date":"2026-10-08","epss":0.0069,"percentile":0.51296}],"risk":0.37605000000000005,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4224","description":"A stack overflow flaw has been discovered in the python pyexpat module. When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. This will result in a program crash."},"relatedVulnerabilities":[{"id":"CVE-2026-4224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4224","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4224","date":"2026-10-08","epss":0.0069,"percentile":0.51296}],"urls":["https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a","https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621","https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785","https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee","https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3","https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768","https://github.com/python/cpython/issues/145986","https://github.com/python/cpython/pull/145987","https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/","http://www.openwall.com/lists/oss-security/2026/03/16/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4224","description":"When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4224","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4224","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4224","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4224","date":"2026-10-08","epss":0.0069,"percentile":0.51296}],"risk":0.37605000000000005,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4224","description":"A stack overflow flaw has been discovered in the python pyexpat module. When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. This will result in a program crash."},"relatedVulnerabilities":[{"id":"CVE-2026-4224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4224","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4224","date":"2026-10-08","epss":0.0069,"percentile":0.51296}],"urls":["https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a","https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621","https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785","https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee","https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3","https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768","https://github.com/python/cpython/issues/145986","https://github.com/python/cpython/pull/145987","https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/","http://www.openwall.com/lists/oss-security/2026/03/16/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4224","description":"When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs."}]},{"artifact":{"id":"d4c0862c711a33a5","cpes":["cpe:2.3:a:jline-builtins:jline-builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:jline_builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline-builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline_builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_builtins:3.30.4:*:*:*:*:*:*:*"],"name":"jline-builtins","purl":"pkg:maven/org.jline/jline-builtins@3.30.4","type":"java-archive","version":"3.30.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/java/kafka/jline-3.30.4.jar:org.jline:jline-builtins","manifestName":"","pomArtifactID":"jline-builtins","archiveDigests":null},"locations":[{"path":"/usr/share/java/kafka/jline-3.30.4.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jline-3.30.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r2xf-8xr9-62gw","versionConstraint":">=3.0.0,<3.30.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-builtins","version":"3.30.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r2xf-8xr9-62gw","fix":{"state":"fixed","versions":["3.30.15"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"3.30.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77422","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77422","date":"2026-10-08","epss":0.00496,"percentile":0.40617}],"risk":0.372,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r2xf-8xr9-62gw","description":"JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping"},"relatedVulnerabilities":[{"id":"CVE-2026-77422","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77422","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77422","date":"2026-10-08","epss":0.00496,"percentile":0.40617}],"urls":["https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15","https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77422","description":"JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(...) and, unless line-regexp mode is used, automatically adds a dot-star prefix and suffix before compiling it with Java's backtracking regular expression engine. The wrapping expands the backtracking search space, so a short nested-quantifier expression evaluated against non-matching input can consume excessive CPU and indefinitely block a command worker, including in remotely exposed shell sessions. This issue is fixed in versions 3.30.15 and 4.3.1."}]},{"artifact":{"id":"2da81090dc4febb6","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.21.5:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5","type":"java-archive","version":"2.21.5","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-core-2.21.5.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"7ec0c8bf8402fa998f64b2009632d6566a42ceb7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-core-2.21.5.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jackson-core-2.21.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.21.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"f867e06c7176411d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-java-micro/jackson-core-2.22.1.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"da7ffb60088d7e8f37ecdd3b617520971cc7b9bf","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/jackson-core-2.22.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/jackson-core-2.22.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.368225,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3276","description":"A flaw was found in the `unicodedata.normalize()` function in Python. This vulnerability allows a remote attacker to cause excessive CPU consumption by providing specially crafted Unicode input. Successful exploitation can lead to a Denial of Service (DoS) on the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.368225,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3276","description":"A flaw was found in the `unicodedata.normalize()` function in Python. This vulnerability allows a remote attacker to cause excessive CPU consumption by providing specially crafted Unicode input. Successful exploitation can lead to a Denial of Service (DoS) on the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"1c27b1fc065b3d30","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=rhel-9.8&upstream=python-pip-21.3.1-2.el9_8.src.rpm","type":"rpm","version":"21.3.1-2.el9_8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"21.3.1-2.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57585","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python-pip","version":"21.3.1-2.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57585","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57585","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57585","date":"2026-10-08","epss":0.00488,"percentile":0.40034}],"risk":0.366,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57585","description":"A flaw was found in MessagePack for Python, a serializer implementation. This vulnerability, categorized as a Use-After-Free (CWE-416), occurs when the Unpacker component is reused after an error. A remote attacker could exploit this by repeatedly providing untrusted input, leading to an out-of-bounds read and a system crash. This can result in a Denial of Service (DoS) attack."},"relatedVulnerabilities":[{"id":"CVE-2026-57585","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57585","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57585","date":"2026-10-08","epss":0.00488,"percentile":0.40034}],"urls":["https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d","https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57585","description":"MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-32636","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-32636","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-32636","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-32636","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-32636","date":"2026-10-08","epss":0.00774,"percentile":0.54361}],"risk":0.35604,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-32636","description":"A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499."},"relatedVulnerabilities":[{"id":"CVE-2023-32636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-32636","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-32636","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-32636","date":"2026-10-08","epss":0.00774,"percentile":0.54361}],"urls":["https://gitlab.gnome.org/GNOME/glib/-/issues/2841","https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835","https://security.netapp.com/advisory/ntap-20231110-0002/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-32636","description":"A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.13-14.el9_8.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-74860","versionConstraint":"< 0:2.9.13-14.el9_8.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-74860","fix":{"state":"fixed","versions":["0:2.9.13-14.el9_8.5"],"available":[{"date":"2026-09-25","kind":"first-observed","version":"0:2.9.13-14.el9_8.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"risk":0.3488,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:71585","link":"https://access.redhat.com/errata/RHSA-2026:71585"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."},"relatedVulnerabilities":[{"id":"CVE-2026-74860","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"urls":["https://access.redhat.com/errata/RHSA-2026:64463","https://access.redhat.com/errata/RHSA-2026:71585","https://access.redhat.com/errata/RHSA-2026:71586","https://access.redhat.com/errata/RHSA-2026:71641","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/security/cve/CVE-2026-74860","https://bugzilla.redhat.com/show_bug.cgi?id=2529697"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.34456,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6019","description":"A flaw was found in Python's `http.cookies` module. The `Morsel.js_output()` function, responsible for generating JavaScript output for cookies, does not properly neutralize the `</script>` HTML sequence. This oversight could allow a remote attacker to inject malicious script into a web page, potentially leading to Cross-Site Scripting (XSS) attacks. Such an attack could result in information disclosure or arbitrary code execution within the user's browser."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.34456,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6019","description":"A flaw was found in Python's `http.cookies` module. The `Morsel.js_output()` function, responsible for generating JavaScript output for cookies, does not properly neutralize the `</script>` HTML sequence. This oversight could allow a remote attacker to inject malicious script into a web page, potentially leading to Cross-Site Scripting (XSS) attacks. Such an attack could result in information disclosure or arbitrary code execution within the user's browser."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"2b82a2f8958cd6a7","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5","type":"java-archive","version":"2.21.5","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"84924990b468233a28214ae2c505a9ec24cd6ea6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.21.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"2b82a2f8958cd6a7","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5","type":"java-archive","version":"2.21.5","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"84924990b468233a28214ae2c505a9ec24cd6ea6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.21.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"13e796f547d90a6a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9e2fb91831cce9cb9262909cd76647508949f232","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"13e796f547d90a6a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9e2fb91831cce9cb9262909cd76647508949f232","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.33462000000000003,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19445","description":"A flaw was found in Python. A remote, unauthenticated TLS client can cause a use-after-free in a server that uses SSLContext.sni_callback to assign a different SSLSocket.context when selecting a certificate per server name, if nothing else keeps the original SSLContext alive. This can crash the server process or result in a call through a freed pointer. Servers that wrap their listening socket with a long-lived SSLContext are not affected. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.33462000000000003,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19445","description":"A flaw was found in Python. A remote, unauthenticated TLS client can cause a use-after-free in a server that uses SSLContext.sni_callback to assign a different SSLSocket.context when selecting a certificate per server name, if nothing else keeps the original SSLContext alive. This can crash the server process or result in a call through a freed pointer. Servers that wrap their listening socket with a long-lived SSLContext are not affected. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-1.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 1:3.5.8-1.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["1:3.5.8-1.el9_8"],"available":[{"date":"2026-09-14","kind":"first-observed","version":"1:3.5.8-1.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.32655,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:67165","link":"https://access.redhat.com/errata/RHSA-2026:67165"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54874","description":"A flaw was found in OpenSSL. Receiving a DTLS (Datagram Transport Layer Security) record for a future epoch while a handshake is in progress causes OpenSSL to buffer an excessive amount of memory. This allows a peer to cause memory exhaustion, eventually resulting in a denial of service, using a small amount of network traffic."},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-27113","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-27113","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-27113","date":"2026-10-08","epss":0.01053,"percentile":0.63313}],"risk":0.321165,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-27113","description":"A flaw was found in libxml2. This vulnerability allows a NULL pointer dereference, leading to a potential crash or denial of service via a crafted XML pattern."},"relatedVulnerabilities":[{"id":"CVE-2025-27113","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-27113","date":"2026-10-08","epss":0.01053,"percentile":0.63313}],"urls":["https://gitlab.gnome.org/GNOME/libxml2/-/issues/861","http://seclists.org/fulldisclosure/2025/Apr/10","http://seclists.org/fulldisclosure/2025/Apr/11","http://seclists.org/fulldisclosure/2025/Apr/12","http://seclists.org/fulldisclosure/2025/Apr/13","http://seclists.org/fulldisclosure/2025/Apr/4","http://seclists.org/fulldisclosure/2025/Apr/5","http://seclists.org/fulldisclosure/2025/Apr/8","http://seclists.org/fulldisclosure/2025/Apr/9","https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html","https://security.netapp.com/advisory/ntap-20250306-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-27113","description":"libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28387","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"risk":0.31590499999999994,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28387","description":"A flaw was found in OpenSSL. An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. This vulnerability could lead to data corruption, application crashes, or, in severe cases, arbitrary code execution. This issue is highly specific and uncommon, as it only affects clients using both PKIX-TA(0)/PKIX-EE(1) and DANE-TA(2) certificate usages and communicating with a server publishing a TLSA record set with both types of records."},"relatedVulnerabilities":[{"id":"CVE-2026-28387","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"urls":["https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b","https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe","https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3","https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7","https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.30928999999999995,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86145","description":"A flaw was found in PCRE2. An out-of-bounds write vulnerability exists in the `pcre2_dfa_match` function due to improper size checking when reusing cached workspace blocks. A remote attacker could exploit this by providing a specially crafted regular expression or a recursive pattern in conjunction with a small heap limit. This could lead to data corruption or potentially arbitrary code execution, compromising the integrity and availability of the system."},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.30928999999999995,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86145","description":"A flaw was found in PCRE2. An out-of-bounds write vulnerability exists in the `pcre2_dfa_match` function due to improper size checking when reusing cached workspace blocks. A remote attacker could exploit this by providing a specially crafted regular expression or a recursive pattern in conjunction with a small heap limit. This could lead to data corruption or potentially arbitrary code execution, compromising the integrity and availability of the system."},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-1.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 1:3.5.8-1.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["1:3.5.8-1.el9_8"],"available":[{"date":"2026-09-14","kind":"first-observed","version":"1:3.5.8-1.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.3087,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:67165","link":"https://access.redhat.com/errata/RHSA-2026:67165"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-63074","description":"A flaw was found in OpenSSL. The CMP (Certificate Management Protocol) implementation does not clear cached additional certificates when an invalid message is received, leading to excessive memory consumption. This allows a malicious client to repeatedly send requests containing unique extra certificates to cause memory exhaustion, eventually resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.5.0-6.el9_8.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"< 0:2.5.0-6.el9_8.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"fixed","versions":["0:2.5.0-6.el9_8.5"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"0:2.5.0-6.el9_8.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.30225,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:72663","link":"https://access.redhat.com/errata/RHSA-2026:72663"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-93990","description":"A flaw was found in Expat. This vulnerability allows a remote attacker to send specially crafted UTF-16 encoded XML data. Due to improper validation of surrogate characters, the parser can be tricked into accepting malformed sequences, which can hide legitimate markup characters. This could enable XML injection attacks, potentially leading to information disclosure or other integrity impacts."},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.298745,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19553","description":"A flaw was found in Python. When establishing secure connections using the SSLContext.wrap_bio() function with hostname checking enabled, the module fails to validate that a target server hostname is supplied. Because of this missing check, certificate hostname verification is silently skipped rather than triggering an error. A remote man-in-the-middle attacker could exploit this defect to spoof trusted endpoints and intercept or tamper with sensitive encrypted traffic."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.298745,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19553","description":"A flaw was found in Python. When establishing secure connections using the SSLContext.wrap_bio() function with hostname checking enabled, the module fails to validate that a target server hostname is supplied. Because of this missing check, certificate hostname verification is silently skipped rather than triggering an error. A remote man-in-the-middle attacker could exploit this defect to spoof trusted endpoints and intercept or tamper with sensitive encrypted traffic."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11468","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-11468","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11468","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-11468","date":"2026-10-08","epss":0.00625,"percentile":0.48333}],"risk":0.296875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-11468","description":"Missing character filtering has been discovered in Python. When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized."},"relatedVulnerabilities":[{"id":"CVE-2025-11468","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11468","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-11468","date":"2026-10-08","epss":0.00625,"percentile":0.48333}],"urls":["https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094","https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2","https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6","https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66","https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0","https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796","https://github.com/python/cpython/issues/143935","https://github.com/python/cpython/pull/143936","https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11468","description":"When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11468","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-11468","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11468","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-11468","date":"2026-10-08","epss":0.00625,"percentile":0.48333}],"risk":0.296875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-11468","description":"Missing character filtering has been discovered in Python. When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized."},"relatedVulnerabilities":[{"id":"CVE-2025-11468","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11468","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-11468","date":"2026-10-08","epss":0.00625,"percentile":0.48333}],"urls":["https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094","https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2","https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6","https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66","https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0","https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796","https://github.com/python/cpython/issues/143935","https://github.com/python/cpython/pull/143936","https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11468","description":"When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized."}]},{"artifact":{"id":"f3e667a0375f3959","cpes":["cpe:2.3:a:xz-libs:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz-libs:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz_libs:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz_libs:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*"],"name":"xz-libs","purl":"pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=rhel-9.8&upstream=xz-5.2.5-8.el9_0.src.rpm","type":"rpm","version":"5.2.5-8.el9_0","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"xz","version":"5.2.5-8.el9_0"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34743","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"xz","version":"5.2.5-8.el9_0"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-34743","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-08","epss":0.00573,"percentile":0.45591}],"risk":0.295095,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-34743","description":"A flaw was found in XZ Utils. When the `lzma_index_decoder()` function processes an empty index, and a subsequent `lzma_index_append()` operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems."},"relatedVulnerabilities":[{"id":"CVE-2026-34743","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-08","epss":0.00573,"percentile":0.45591}],"urls":["https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87","https://github.com/tukaani-project/xz/releases/tag/v5.8.3","https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv","http://www.openwall.com/lists/oss-security/2026/03/31/13","https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34743","description":"XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-12781","description":"A flaw was found in the base64 module in the Python standard library. The b64decode, standard_b64decode and urlsafe_b64decode functions will always accept the '+' and '/' characters even when an alternative base64 alphabet is specified via the altchars parameter that excludes them. This input validation bypass allows malformed or unexpected data to pass through decoding filters, potentially causing logical errors or data integrity issues in applications relying on strict character sets."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-12781","description":"A flaw was found in the base64 module in the Python standard library. The b64decode, standard_b64decode and urlsafe_b64decode functions will always accept the '+' and '/' characters even when an alternative base64 alphabet is specified via the altchars parameter that excludes them. This input validation bypass allows malformed or unexpected data to pass through decoding filters, potentially causing logical errors or data integrity issues in applications relying on strict character sets."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-2.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 1:3.5.8-2.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["1:3.5.8-2.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1:3.5.8-2.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.29055,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:77396","link":"https://access.redhat.com/errata/RHSA-2026:77396"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84782","description":"A flaw was found in OpenSSL. The Datagram Transport Layer Security (DTLS) retransmission mechanism fails to properly handle handshake message writes that are suspended before completion. A remote attacker could exploit this vulnerability during handshake message retransmission, causing OpenSSL to read past the message buffer or overwrite internal state required to resume writing. This issue can result in information disclosure through out-of-bounds memory reads or cause a Denial of Service (DoS) by crashing the process."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"2b82a2f8958cd6a7","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.5:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5","type":"java-archive","version":"2.21.5","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"84924990b468233a28214ae2c505a9ec24cd6ea6","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jackson-databind-2.21.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.19.0,<2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.21.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.21.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"13e796f547d90a6a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9e2fb91831cce9cb9262909cd76647508949f232","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/jackson-databind-2.22.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.22.0,<2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.22.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.22.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.26882999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19672","description":"A flaw was found in the Python `tarfile` module. This vulnerability allows an attacker to create empty directories outside of the intended extraction destination on POSIX (Portable Operating System Interface) platforms. This occurs when processing a specially crafted archive containing member names that use directory traversal sequences (e.g., `../`) to leave and then re-enter the target directory. While only empty directories are created outside the destination, this can lead to unintended file system modifications."},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.26882999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19672","description":"A flaw was found in the Python `tarfile` module. This vulnerability allows an attacker to create empty directories outside of the intended extraction destination on POSIX (Portable Operating System Interface) platforms. This occurs when processing a specially crafted archive containing member names that use directory traversal sequences (e.g., `../`) to leave and then re-enter the target directory. While only empty directories are created outside the destination, this can lead to unintended file system modifications."},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15282","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-15282","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15282","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15282","date":"2026-10-08","epss":0.00545,"percentile":0.43998}],"risk":0.26705,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15282","description":"Missing newline filtering has been discovered in Python. User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype."},"relatedVulnerabilities":[{"id":"CVE-2025-15282","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15282","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15282","date":"2026-10-08","epss":0.00545,"percentile":0.43998}],"urls":["https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0","https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38","https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80","https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47","https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a","https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f","https://github.com/python/cpython/issues/143925","https://github.com/python/cpython/pull/143926","https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15282","description":"User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15282","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-15282","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15282","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15282","date":"2026-10-08","epss":0.00545,"percentile":0.43998}],"risk":0.26705,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15282","description":"Missing newline filtering has been discovered in Python. User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype."},"relatedVulnerabilities":[{"id":"CVE-2025-15282","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15282","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15282","date":"2026-10-08","epss":0.00545,"percentile":0.43998}],"urls":["https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0","https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38","https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80","https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47","https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a","https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f","https://github.com/python/cpython/issues/143925","https://github.com/python/cpython/pull/143926","https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15282","description":"User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.26695,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1502","description":"A flaw was found in Python. This vulnerability allows for the injection of extra information into HTTP communication. Specifically, the system does not properly prevent special characters (carriage return and line feed) from being included in HTTP client proxy tunnel headers or host fields."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.26695,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1502","description":"A flaw was found in Python. This vulnerability allows for the injection of extra information into HTTP communication. Specifically, the system does not properly prevent special characters (carriage return and line feed) from being included in HTTP client proxy tunnel headers or host fields."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76641","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-76641","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76641","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76641","date":"2026-10-08","epss":0.00353,"percentile":0.26927}],"risk":0.26475,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-76641","description":"A flaw was found in Expat. Attackers can exploit an out-of-bounds read vulnerability by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. This can lead to memory corruption. Specifically, a mismatch in struct sizes can cause a read past memory boundaries, potentially resulting in a denial of service (DoS) due to a segfault or incorrect handling of XML attributes."},"relatedVulnerabilities":[{"id":"CVE-2026-76641","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76641","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76641","date":"2026-10-08","epss":0.00353,"percentile":0.26927}],"urls":["https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf","https://github.com/libexpat/libexpat/pull/1331","https://www.vulncheck.com/advisories/expat-out-of-bounds-read-via-dtdcopy"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76641","description":"Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.264,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75804","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) due to missing connection-level flow control enforcement in the QUIC protocol implementation. By opening multiple streams that respect individual stream limits while preventing data consumption, the attacker can force the system to buffer far more data than permitted by the connection limit. This excessive memory allocation can exhaust available system resources and degrade or terminate the service."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"1c27b1fc065b3d30","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=rhel-9.8&upstream=python-pip-21.3.1-2.el9_8.src.rpm","type":"rpm","version":"21.3.1-2.el9_8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"21.3.1-2.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-45803","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python-pip","version":"21.3.1-2.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-45803","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45803","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2023-45803","date":"2026-10-08","epss":0.00544,"percentile":0.43901}],"risk":0.25024,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-45803","description":"A flaw was found in urllib3, an HTTP client library for Python. urllib3 doesn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303, after changing the method in a request from one that could accept a request body such as `POST` to `GET`, as is required by HTTP RFCs. This issue requires a previously trusted service to become compromised in order to have an impact on confidentiality, therefore, the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies; if this is the case, this vulnerability isn't exploitable."},"relatedVulnerabilities":[{"id":"CVE-2023-45803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45803","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2023-45803","date":"2026-10-08","epss":0.00544,"percentile":0.43901}],"urls":["https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9","https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/","https://www.rfc-editor.org/rfc/rfc9110.html#name-get","https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45803","description":"urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body."}]},{"artifact":{"id":"d4c0862c711a33a5","cpes":["cpe:2.3:a:jline-builtins:jline-builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:jline_builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline-builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline_builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-builtins:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_builtins:3.30.4:*:*:*:*:*:*:*"],"name":"jline-builtins","purl":"pkg:maven/org.jline/jline-builtins@3.30.4","type":"java-archive","version":"3.30.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/java/kafka/jline-3.30.4.jar:org.jline:jline-builtins","manifestName":"","pomArtifactID":"jline-builtins","archiveDigests":null},"locations":[{"path":"/usr/share/java/kafka/jline-3.30.4.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jline-3.30.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ph9c-7hw9-vhhw","versionConstraint":">=3.0.0,<3.30.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-builtins","version":"3.30.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-ph9c-7hw9-vhhw","fix":{"state":"fixed","versions":["3.30.15"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"3.30.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77421","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77421","date":"2026-10-08","epss":0.00434,"percentile":0.35636}],"risk":0.24955,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ph9c-7hw9-vhhw","description":"JLine: ReDoS in Nano Editor Regex Search Mode"},"relatedVulnerabilities":[{"id":"CVE-2026-77421","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77421","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77421","date":"2026-10-08","epss":0.00434,"percentile":0.35636}],"urls":["https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15","https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77421","description":"JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A nested-quantifier expression evaluated against non-matching buffer content can consume excessive CPU and indefinitely block the editor session thread, and remote multi-user deployments can lose a worker thread for each affected session. This issue is fixed in versions 3.30.15 and 4.3.1."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3644","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-3644","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3644","date":"2026-10-08","epss":0.00478,"percentile":0.39324}],"risk":0.24856,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3644","description":"A control character validation flaw has been discovered in the Python http.cookie module. The Morsel.update(), |= operator, and unpickling paths were not patched to resolve  CVE-2026-0672, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output()."},"relatedVulnerabilities":[{"id":"CVE-2026-3644","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-3644","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3644","date":"2026-10-08","epss":0.00478,"percentile":0.39324}],"urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output()."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3644","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-3644","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3644","date":"2026-10-08","epss":0.00478,"percentile":0.39324}],"risk":0.24856,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3644","description":"A control character validation flaw has been discovered in the Python http.cookie module. The Morsel.update(), |= operator, and unpickling paths were not patched to resolve  CVE-2026-0672, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output()."},"relatedVulnerabilities":[{"id":"CVE-2026-3644","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-3644","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3644","date":"2026-10-08","epss":0.00478,"percentile":0.39324}],"urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output()."}]},{"artifact":{"id":"23e3d9feac1cb13c","cpes":["cpe:2.3:a:libgcc:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-46195","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2021-46195","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"risk":0.24538499999999996,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-46195","description":"A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash."},"relatedVulnerabilities":[{"id":"CVE-2021-46195","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-46195","description":"GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources."}]},{"artifact":{"id":"62a2970ccab3dd86","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-46195","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2021-46195","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"risk":0.24538499999999996,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-46195","description":"A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash."},"relatedVulnerabilities":[{"id":"CVE-2021-46195","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-46195","description":"GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources."}]},{"artifact":{"id":"1c27b1fc065b3d30","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=rhel-9.8&upstream=python-pip-21.3.1-2.el9_8.src.rpm","type":"rpm","version":"21.3.1-2.el9_8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"21.3.1-2.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-50181","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python-pip","version":"21.3.1-2.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-50181","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50181","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50181","date":"2026-10-08","epss":0.00474,"percentile":0.39002}],"risk":0.24411000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-50181","description":"A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration to manipulate request flows and disrupt service. This bypass occurs through improper handling of retry parameters during PoolManager instantiation. This issue can reult in a denial of service or unintended data exposure due to altered request destinations."},"relatedVulnerabilities":[{"id":"CVE-2025-50181","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50181","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50181","date":"2026-10-08","epss":0.00474,"percentile":0.39002}],"urls":["https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857","https://github.com/urllib3/urllib3/releases/tag/2.5.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181","description":"urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4360","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-4360","date":"2026-10-08","epss":0.00481,"percentile":0.39489}],"risk":0.2405,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4360","description":"A flaw was found in the Python `Tarfile.extract()` function. This vulnerability occurs when processing untrusted tar files containing hardlinks, as the `filter` parameter is not correctly enforced. An attacker could exploit this to write files with unintended user or group ownership, potentially leading to unauthorized modifications or privilege issues on the system."},"relatedVulnerabilities":[{"id":"CVE-2026-4360","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-4360","date":"2026-10-08","epss":0.00481,"percentile":0.39489}],"urls":["https://github.com/python/cpython/commit/0367912be336348b30572f8029cec4a282782d92","https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0","https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301","https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a","https://github.com/python/cpython/commit/cf23b9153181062150d061468b6d24af33fe214f","https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44","https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e","https://github.com/python/cpython/issues/151987","https://github.com/python/cpython/pull/151988","https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4360","description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4360","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-4360","date":"2026-10-08","epss":0.00481,"percentile":0.39489}],"risk":0.2405,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4360","description":"A flaw was found in the Python `Tarfile.extract()` function. This vulnerability occurs when processing untrusted tar files containing hardlinks, as the `filter` parameter is not correctly enforced. An attacker could exploit this to write files with unintended user or group ownership, potentially leading to unauthorized modifications or privilege issues on the system."},"relatedVulnerabilities":[{"id":"CVE-2026-4360","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-4360","date":"2026-10-08","epss":0.00481,"percentile":0.39489}],"urls":["https://github.com/python/cpython/commit/0367912be336348b30572f8029cec4a282782d92","https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0","https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301","https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a","https://github.com/python/cpython/commit/cf23b9153181062150d061468b6d24af33fe214f","https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44","https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e","https://github.com/python/cpython/issues/151987","https://github.com/python/cpython/pull/151988","https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4360","description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.23793,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54873","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted network packets to a QUIC protocol endpoint. Because the QUIC stack retains memory in packet buffers until the receiving application reads the stream data, an attacker can manipulate data transfers to keep these buffers allocated indefinitely. This behavior leads to excessive memory consumption and can exhaust available system resources."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-13176","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-13176","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"risk":0.23600500000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-13176","description":"A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected."},"relatedVulnerabilities":[{"id":"CVE-2024-13176","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.1,"impactScore":3.4,"exploitabilityScore":0.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"urls":["https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844","https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467","https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902","https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65","https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f","https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded","https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86","https://openssl-library.org/news/secadv/20250120.txt","http://www.openwall.com/lists/oss-security/2025/01/20/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html","https://security.netapp.com/advisory/ntap-20250124-0005/","https://security.netapp.com/advisory/ntap-20250418-0010/","https://security.netapp.com/advisory/ntap-20250502-0006/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-13176","description":"Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue."}]},{"artifact":{"id":"1c27b1fc065b3d30","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=rhel-9.8&upstream=python-pip-21.3.1-2.el9_8.src.rpm","type":"rpm","version":"21.3.1-2.el9_8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"21.3.1-2.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45409","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python-pip","version":"21.3.1-2.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45409","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45409","date":"2026-10-08","epss":0.00457,"percentile":0.37632}],"risk":0.23535500000000004,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45409","description":"A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding function. This could cause the system to consume significant resources, leading to a Denial of Service (DoS), where the affected application becomes unavailable to legitimate users. This issue stems from an incomplete fix for a previously identified vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2026-45409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45409","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45409","date":"2026-10-08","epss":0.00457,"percentile":0.37632}],"urls":["https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409","description":"Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application."}]},{"artifact":{"id":"dd995e0ac7dd3a05","cpes":["cpe:2.3:a:harfbuzz:harfbuzz:2.7.4-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:harfbuzz:2.7.4-10.el9:*:*:*:*:*:*:*"],"name":"harfbuzz","purl":"pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=rhel-9.8&upstream=harfbuzz-2.7.4-10.el9.src.rpm","type":"rpm","version":"2.7.4-10.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-22693","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"harfbuzz","version":"0:2.7.4-10.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-22693","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22693","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-22693","date":"2026-10-08","epss":0.00452,"percentile":0.37259}],"risk":0.23278000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-22693","description":"A null pointer dereference vector has been discovered in the harfbuzz package. A null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh:1672-1673. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault."},"relatedVulnerabilities":[{"id":"CVE-2026-22693","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22693","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-22693","date":"2026-10-08","epss":0.00452,"percentile":0.37259}],"urls":["https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae","https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww","http://www.openwall.com/lists/oss-security/2026/01/11/1","http://www.openwall.com/lists/oss-security/2026/01/12/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22693","description":"HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0."}]},{"artifact":{"id":"23e3d9feac1cb13c","cpes":["cpe:2.3:a:libgcc:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.230505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"62a2970ccab3dd86","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.230505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0672","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0672","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0672","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0672","date":"2026-10-08","epss":0.00469,"percentile":0.38616}],"risk":0.22981,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0672","description":"An injection flaw has been discovered in Python. When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters."},"relatedVulnerabilities":[{"id":"CVE-2026-0672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0672","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0672","date":"2026-10-08","epss":0.00469,"percentile":0.38616}],"urls":["https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172","https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440","https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d","https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca","https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70","https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85","https://github.com/python/cpython/issues/143919","https://github.com/python/cpython/pull/143920","https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0672","description":"When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0672","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0672","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0672","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0672","date":"2026-10-08","epss":0.00469,"percentile":0.38616}],"risk":0.22981,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0672","description":"An injection flaw has been discovered in Python. When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters."},"relatedVulnerabilities":[{"id":"CVE-2026-0672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0672","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0672","date":"2026-10-08","epss":0.00469,"percentile":0.38616}],"urls":["https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172","https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440","https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d","https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca","https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70","https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85","https://github.com/python/cpython/issues/143919","https://github.com/python/cpython/pull/143920","https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0672","description":"When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42765","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42765","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"risk":0.21226500000000004,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42765","description":"A flaw was found in OpenSSL. When an application is configured with specific non-default settings for certificate verification, including both Online Certificate Status Protocol (OCSP) response checking and partial chain verification, a NULL dereference can occur. This vulnerability can be triggered if the certificate chain lacks a self-signed trusted anchor, causing the application to crash. This leads to a Denial of Service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-42765","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"urls":["https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334","https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42765","description":"Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"655202f633f6833d","cpes":["cpe:2.3:a:libXrender:libXrender:0.9.10-16.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libXrender:0.9.10-16.el9_8.1:*:*:*:*:*:*:*"],"name":"libXrender","purl":"pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=rhel-9.8&upstream=libXrender-0.9.10-16.el9_8.1.src.rpm","type":"rpm","version":"0.9.10-16.el9_8.1","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-88807","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libXrender","version":"0:0.9.10-16.el9_8.1"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-88807","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88807","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88807","date":"2026-10-08","epss":0.0026,"percentile":0.16256}],"risk":0.20539999999999997,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-88807","description":"A flaw was found in libXrender. Malicious X servers can exploit a heap overflow vulnerability in the RenderQueryPictFormats function. This allows them to inject arbitrary code into connected X clients, potentially leading to unauthorized control over the client's system."},"relatedVulnerabilities":[{"id":"CVE-2026-88807","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88807","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88807","date":"2026-10-08","epss":0.0026,"percentile":0.16256}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88807","description":"A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients."}]},{"artifact":{"id":"1c27b1fc065b3d30","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=rhel-9.8&upstream=python-pip-21.3.1-2.el9_8.src.rpm","type":"rpm","version":"21.3.1-2.el9_8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"21.3.1-2.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-50182","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python-pip","version":"21.3.1-2.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-50182","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50182","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50182","date":"2026-10-08","epss":0.00393,"percentile":0.31356}],"risk":0.202395,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-50182","description":"A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can enable a remote attacker to control the redirect destination, leading to arbitrary URL redirection. Consequently, an attacker can redirect users to malicious websites. This \nvulnerability stems from a failure to constrain the redirect target."},"relatedVulnerabilities":[{"id":"CVE-2025-50182","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50182","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50182","date":"2026-10-08","epss":0.00393,"percentile":0.31356}],"urls":["https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f","https://github.com/urllib3/urllib3/releases/tag/2.5.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75806","description":"A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by terminating an active Datagram Transport Layer Security (DTLS) session. By sending an undersized network packet that is shorter than the expected cryptographic overhead, the record processing layer fails to validate the packet length and misinterprets the packet as an internal error rather than an authentication failure. This improper handling triggers a fatal alert that unexpectedly closes the targeted connection without requiring valid encryption keys."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1489","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1489","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1489","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1489","date":"2026-10-08","epss":0.00371,"percentile":0.29003}],"risk":0.19292000000000004,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1489","description":"A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable."},"relatedVulnerabilities":[{"id":"CVE-2026-1489","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1489","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1489","date":"2026-10-08","epss":0.00371,"percentile":0.29003}],"urls":["https://access.redhat.com/security/cve/CVE-2026-1489","https://bugzilla.redhat.com/show_bug.cgi?id=2433348","https://gitlab.gnome.org/GNOME/glib/-/issues/3872","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1489","description":"A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1795","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-1795","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1795","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-1795","date":"2026-10-08","epss":0.00628,"percentile":0.48461}],"risk":0.19154000000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-1795","description":"A flaw was found in Python. When a separating comma ends up on a folded line during an address list folding of email headers, the comma is unintentionally unicode encoded. The expected behavior is that the separating comma remains unencoded. This can result in the address header being misinterpreted by some mail servers."},"relatedVulnerabilities":[{"id":"CVE-2025-1795","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1795","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-1795","date":"2026-10-08","epss":0.00628,"percentile":0.48461}],"urls":["https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48","https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593","https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74","https://github.com/python/cpython/commit/a4ef689ce670684ec132204b1cd03720c8e0a03d","https://github.com/python/cpython/commit/d4df3c55e4c5513947f907f24766b34d2ae8c090","https://github.com/python/cpython/issues/100884","https://github.com/python/cpython/pull/100885","https://github.com/python/cpython/pull/119099","https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1795","description":"During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1795","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-1795","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1795","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-1795","date":"2026-10-08","epss":0.00628,"percentile":0.48461}],"risk":0.19154000000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-1795","description":"A flaw was found in Python. When a separating comma ends up on a folded line during an address list folding of email headers, the comma is unintentionally unicode encoded. The expected behavior is that the separating comma remains unencoded. This can result in the address header being misinterpreted by some mail servers."},"relatedVulnerabilities":[{"id":"CVE-2025-1795","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1795","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-1795","date":"2026-10-08","epss":0.00628,"percentile":0.48461}],"urls":["https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48","https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593","https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74","https://github.com/python/cpython/commit/a4ef689ce670684ec132204b1cd03720c8e0a03d","https://github.com/python/cpython/commit/d4df3c55e4c5513947f907f24766b34d2ae8c090","https://github.com/python/cpython/issues/100884","https://github.com/python/cpython/pull/100885","https://github.com/python/cpython/pull/119099","https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1795","description":"During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers."}]},{"artifact":{"id":"448588eb4147df6f","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v53-57pg-c464","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v53-57pg-c464","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","https://nvd.nist.gov/vuln/detail/CVE-2026-106452","https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v53-57pg-c464","description":"yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header"},"relatedVulnerabilities":[{"id":"CVE-2026-106452","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"9d4b5e84721dd1cf","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/lz4-java-1.11.1.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v53-57pg-c464","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v53-57pg-c464","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","https://nvd.nist.gov/vuln/detail/CVE-2026-106452","https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v53-57pg-c464","description":"yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header"},"relatedVulnerabilities":[{"id":"CVE-2026-106452","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"448588eb4147df6f","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cx8-rjf8-pr8g","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cx8-rjf8-pr8g","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","https://nvd.nist.gov/vuln/detail/CVE-2026-106453","https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cx8-rjf8-pr8g","description":"yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError"},"relatedVulnerabilities":[{"id":"CVE-2026-106453","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"9d4b5e84721dd1cf","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/lz4-java-1.11.1.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cx8-rjf8-pr8g","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cx8-rjf8-pr8g","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","https://nvd.nist.gov/vuln/detail/CVE-2026-106453","https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cx8-rjf8-pr8g","description":"yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError"},"relatedVulnerabilities":[{"id":"CVE-2026-106453","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"448588eb4147df6f","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm45-99xc-r7wv","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gm45-99xc-r7wv","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","https://nvd.nist.gov/vuln/detail/CVE-2026-106450","https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm45-99xc-r7wv","description":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-106450","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"9d4b5e84721dd1cf","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/lz4-java-1.11.1.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm45-99xc-r7wv","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gm45-99xc-r7wv","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","https://nvd.nist.gov/vuln/detail/CVE-2026-106450","https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm45-99xc-r7wv","description":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-106450","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.18966000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-102633","description":"A flaw was found in expat. On 32-bit systems, an integer overflow occurs within the expat_realloc memory allocation function when calculating buffer sizes. A remote attacker can exploit this vulnerability by supplying specially crafted XML input to an application that processes data with the library. Successful exploitation can lead to a Denial of Service (DoS) or memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"a6c320bbdb2151ba","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=libpng-1.6.37-15.el9_8.2.src.rpm","type":"rpm","version":"2:1.6.37-15.el9_8.2","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-40930","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libpng","version":"2:1.6.37-15.el9_8.2"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-40930","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40930","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40930","date":"2026-10-08","epss":0.00355,"percentile":0.27208}],"risk":0.18460000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-40930","description":"A flaw was found in libpng, a library used for processing PNG (Portable Network Graphics) image files. In version 1.8.0, a remote attacker could provide a specially crafted APNG (Animated Portable Network Graphics) file. This flaw allows attacker-controlled data within an ignored chunk to be reinterpreted as a new chunk header, leading to a low impact on data integrity and availability. This could result in unexpected application behavior or a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-40930","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40930","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40930","date":"2026-10-08","epss":0.00355,"percentile":0.27208}],"urls":["https://github.com/pnggroup/libpng/commit/faf06924688b62d7c1654b5ceddedbde66ffadb4","https://github.com/pnggroup/libpng/security/advisories/GHSA-c4v6-gxrq-6g2x","http://www.openwall.com/lists/oss-security/2026/05/15/21"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40930","description":"LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0989","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0989","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0989","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0989","date":"2026-10-08","epss":0.00538,"percentile":0.43534}],"risk":0.18023,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0989","description":"A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk."},"relatedVulnerabilities":[{"id":"CVE-2026-0989","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0989","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0989","date":"2026-10-08","epss":0.00538,"percentile":0.43534}],"urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0989","https://bugzilla.redhat.com/show_bug.cgi?id=2429933","https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0989","description":"A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8674","description":"A flaw was found in the GNU C Library (glibc) DNS stub resolver. This vulnerability allows a remote attacker on the local network to cause a denial of service by providing a specially crafted, excessively long search domain. When the resolver attempts to initialize with this long domain from /etc/resolv.conf or the LOCALDOMAIN environment variable, it triggers an assertion failure, which aborts the process. This can be exploited without privileges on the target system, potentially through network configuration mechanisms like DHCP or a VPN server."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8674","description":"A flaw was found in the GNU C Library (glibc) DNS stub resolver. This vulnerability allows a remote attacker on the local network to cause a denial of service by providing a specially crafted, excessively long search domain. When the resolver attempts to initialize with this long domain from /etc/resolv.conf or the LOCALDOMAIN environment variable, it triggers an assertion failure, which aborts the process. This can be exploited without privileges on the target system, potentially through network configuration mechanisms like DHCP or a VPN server."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8674","description":"A flaw was found in the GNU C Library (glibc) DNS stub resolver. This vulnerability allows a remote attacker on the local network to cause a denial of service by providing a specially crafted, excessively long search domain. When the resolver attempts to initialize with this long domain from /etc/resolv.conf or the LOCALDOMAIN environment variable, it triggers an assertion failure, which aborts the process. This can be exploited without privileges on the target system, potentially through network configuration mechanisms like DHCP or a VPN server."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42772","description":"A flaw was found in OpenSSL. A remote attacker who establishes a QUIC network connection can cause a Denial of Service (DoS) by sending specially sequenced, out-of-order stream frames. Because the stream reassembly mechanism handles non-sequential data fragments inefficiently, processing these frames forces the server to consume excessive CPU resources. Consequently, an attacker can exhaust system processing capacity using minimal network bandwidth."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.16157000000000002,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-103111","description":"A flaw was found in pcre2. When an application processes attacker-controlled regular expressions using certain Just-In-Time (JIT) compiler interfaces, an out-of-bounds write with arbitrary data can occur. An attacker could exploit this vulnerability to achieve arbitrary code execution, corrupt memory, or cause a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.16157000000000002,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-103111","description":"A flaw was found in pcre2. When an application processes attacker-controlled regular expressions using certain Just-In-Time (JIT) compiler interfaces, an out-of-bounds write with arbitrary data can occur. An attacker could exploit this vulnerability to achieve arbitrary code execution, corrupt memory, or cause a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1484","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1484","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1484","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1484","date":"2026-10-08","epss":0.00346,"percentile":0.26123}],"risk":0.15916,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1484","description":"A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably."},"relatedVulnerabilities":[{"id":"CVE-2026-1484","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1484","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1484","date":"2026-10-08","epss":0.00346,"percentile":0.26123}],"urls":["https://access.redhat.com/security/cve/CVE-2026-1484","https://bugzilla.redhat.com/show_bug.cgi?id=2433259","https://gitlab.gnome.org/GNOME/glib/-/issues/3870","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1484","description":"A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably."}]},{"artifact":{"id":"1c27b1fc065b3d30","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=rhel-9.8&upstream=python-pip-21.3.1-2.el9_8.src.rpm","type":"rpm","version":"21.3.1-2.el9_8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"21.3.1-2.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13346","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python-pip","version":"21.3.1-2.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13346","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L","metrics":{"baseScore":5.9,"impactScore":4.8,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-08","epss":0.00292,"percentile":0.19984}],"risk":0.15914,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13346","description":"A flaw was found in pip. When processing doubly-encoded package URLs from malicious package indexes, pip incorrectly handles the file paths. A remote attacker could exploit this by convincing a user to download or install a package from such an index. This could allow for files to be installed to arbitrary locations on the system, potentially leading to system compromise. This vulnerability primarily affects users utilizing the `pip download` command with the `--only-binary` option."},"relatedVulnerabilities":[{"id":"CVE-2026-13346","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-08","epss":0.00292,"percentile":0.19984}],"urls":["https://github.com/pypa/pip/pull/14110","https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/","http://www.openwall.com/lists/oss-security/2026/07/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13346","description":"pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-3360","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-3360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-3360","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-3360","date":"2026-10-08","epss":0.00475,"percentile":0.39072}],"risk":0.159125,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-3360","description":"A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function."},"relatedVulnerabilities":[{"id":"CVE-2025-3360","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-3360","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-3360","date":"2026-10-08","epss":0.00475,"percentile":0.39072}],"urls":["https://access.redhat.com/security/cve/CVE-2025-3360","https://bugzilla.redhat.com/show_bug.cgi?id=2357754","https://gitlab.gnome.org/GNOME/glib/-/issues/3647","https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html","https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-3360","description":"A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function."}]},{"artifact":{"id":"23e3d9feac1cb13c","cpes":["cpe:2.3:a:libgcc:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.15,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"62a2970ccab3dd86","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.15,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"bb1caebf00bfd67f","cpes":["cpe:2.3:a:libX11:libX11:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11","purl":"pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-88806","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"0:1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-88806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"risk":0.14925,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-88806","description":"A flaw was found in libX11. A heap-based buffer overflow vulnerability exists during the handling of XkbGetMap replies. A remote attacker, by operating a malicious X server, could exploit this flaw to potentially execute arbitrary code or cause a denial of service on the client system. User interaction is required for exploitation."},"relatedVulnerabilities":[{"id":"CVE-2026-88806","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."}]},{"artifact":{"id":"6a1cd4ae8b36edce","cpes":["cpe:2.3:a:libX11-common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11-common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11-common","purl":"pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libX11","version":"1.8.12-1.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88806","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-88806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"risk":0.14925,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-88806","description":"A flaw was found in libX11. A heap-based buffer overflow vulnerability exists during the handling of XkbGetMap replies. A remote attacker, by operating a malicious X server, could exploit this flaw to potentially execute arbitrary code or cause a denial of service on the client system. User interaction is required for exploitation."},"relatedVulnerabilities":[{"id":"CVE-2026-88806","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.14873,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89157","description":"A flaw was found in PCRE2. On 32-bit platforms, an attacker can provide a specially crafted large pattern, leading to an out-of-bounds write within the pcre2_pattern_convert function. This vulnerability can result in high integrity impact, such as data corruption, and potentially a low availability impact, causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.14873,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89157","description":"A flaw was found in PCRE2. On 32-bit platforms, an attacker can provide a specially crafted large pattern, leading to an out-of-bounds write within the pcre2_pattern_convert function. This vulnerability can result in high integrity impact, such as data corruption, and potentially a low availability impact, causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0988","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0988","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0988","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0988","date":"2026-10-08","epss":0.00441,"percentile":0.36292}],"risk":0.14773499999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0988","description":"A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-0988","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0988","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0988","date":"2026-10-08","epss":0.00441,"percentile":0.36292}],"urls":["https://access.redhat.com/errata/RHSA-2026:7461","https://access.redhat.com/security/cve/CVE-2026-0988","https://bugzilla.redhat.com/show_bug.cgi?id=2429886","https://gitlab.gnome.org/GNOME/glib/-/issues/3851"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0988","description":"A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS)."}]},{"artifact":{"id":"1c9a349fe96f859f","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=sqlite-3.34.1-11.el9_8.src.rpm","type":"rpm","version":"3.34.1-11.el9_8","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.34.1-11.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-0232","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"sqlite","version":"3.34.1-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-0232","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0232","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-0232","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-0232","date":"2026-10-08","epss":0.00381,"percentile":0.29975}],"risk":0.146685,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-0232","description":"A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2024-0232","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0232","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-0232","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-0232","date":"2026-10-08","epss":0.00381,"percentile":0.29975}],"urls":["https://access.redhat.com/security/cve/CVE-2024-0232","https://bugzilla.redhat.com/show_bug.cgi?id=2243754","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/","https://security.netapp.com/advisory/ntap-20240315-0007/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0232","description":"A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.14497000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-72897","description":"A flaw was found in openssl. When a server replaces its security context during an active Transport Layer Security (TLS) handshake, it fails to update the internal capacity tracking for cryptographic signature algorithms. A remote peer can exploit this issue by advertising specific signature algorithms, causing out-of-bounds memory reads and writes on the server heap. This vulnerability can corrupt internal memory and terminate the process, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.14333500000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54872","description":"A flaw was found in OpenSSL. A timing side-channel vulnerability in generic elliptic curve scalar multiplication allows an attacker to recover private cryptographic keys. When performing signature operations, such as the Elliptic Curve Digital Signature Algorithm (ECDSA) or SM2, using curves without dedicated constant-time implementations, variations in processing time leak information about the per-signature secret value. By measuring the duration of numerous signing operations, an attacker can analyze these timing differences to reconstruct the private signing key."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-31789","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-31789","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"risk":0.143,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-31789","description":"A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment."},"relatedVulnerabilities":[{"id":"CVE-2026-31789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"urls":["https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31789","description":"Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.14259,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54875","description":"A flaw was found in OpenSSL. The optimized scalar point multiplication used for SM2 cryptographic operations on ARM64 and RISC-V architectures does not execute in constant time. An attacker capable of measuring execution times or observing processor cache-access patterns can exploit this side channel during decryption or digital signature generation. This vulnerability allows the attacker to deduce sensitive private keys or signature nonces, leading to information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.14202499999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89158","description":"A flaw was found in PCRE2. On 32-bit platforms, an integer overflow in the `pcre2_compile_32` function can lead to an out-of-bounds write. This vulnerability could allow a remote attacker to achieve a high integrity impact and a low availability impact, potentially leading to data corruption or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.14202499999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89158","description":"A flaw was found in PCRE2. On 32-bit platforms, an integer overflow in the `pcre2_compile_32` function can lead to an out-of-bounds write. This vulnerability could allow a remote attacker to achieve a high integrity impact and a low availability impact, potentially leading to data corruption or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"579132f61ab96cf6","cpes":["cpe:2.3:a:redhat:libXi:1.7.10-8.el9:*:*:*:*:*:*:*","cpe:2.3:a:libXi:libXi:1.7.10-8.el9:*:*:*:*:*:*:*"],"name":"libXi","purl":"pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=rhel-9.8&upstream=libXi-1.7.10-8.el9.src.rpm","type":"rpm","version":"1.7.10-8.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-93542","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libXi","version":"0:1.7.10-8.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-93542","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93542","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93542","date":"2026-10-08","epss":0.00246,"percentile":0.14516}],"risk":0.14145,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-93542","description":"A flaw was found in libXi. An out-of-bounds read vulnerability occurs during the parsing of X Input Extension (XI2) device class data. A malicious X server can exploit this vulnerability by sending specially crafted class responses to a connected client application. This causes the client to read beyond memory boundaries and crash, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-93542","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93542","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93542","date":"2026-10-08","epss":0.00246,"percentile":0.14516}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=f499944ad595b9bd7e7571c810842244caf150aa"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93542","description":"An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client."}]},{"artifact":{"id":"579132f61ab96cf6","cpes":["cpe:2.3:a:redhat:libXi:1.7.10-8.el9:*:*:*:*:*:*:*","cpe:2.3:a:libXi:libXi:1.7.10-8.el9:*:*:*:*:*:*:*"],"name":"libXi","purl":"pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=rhel-9.8&upstream=libXi-1.7.10-8.el9.src.rpm","type":"rpm","version":"1.7.10-8.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-93543","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libXi","version":"0:1.7.10-8.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-93543","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93543","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93543","date":"2026-10-08","epss":0.00246,"percentile":0.14516}],"risk":0.14145,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-93543","description":"A flaw was found in libXi. An out-of-bounds read vulnerability in the X Input 2 (XI2) class parser allows a malicious X server to cause a Denial of Service (DoS) by crashing connected client applications. When an application receives and processes specially crafted input from the server, insufficient boundary checking causes the client to read beyond memory limits and terminate unexpectedly."},"relatedVulnerabilities":[{"id":"CVE-2026-93543","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93543","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93543","date":"2026-10-08","epss":0.00246,"percentile":0.14516}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=e2089ab748828273f916bbffd4e65b506aa50fdc"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93543","description":"An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client."}]},{"artifact":{"id":"579132f61ab96cf6","cpes":["cpe:2.3:a:redhat:libXi:1.7.10-8.el9:*:*:*:*:*:*:*","cpe:2.3:a:libXi:libXi:1.7.10-8.el9:*:*:*:*:*:*:*"],"name":"libXi","purl":"pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=rhel-9.8&upstream=libXi-1.7.10-8.el9.src.rpm","type":"rpm","version":"1.7.10-8.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-93541","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libXi","version":"0:1.7.10-8.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-93541","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93541","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93541","date":"2026-10-08","epss":0.00245,"percentile":0.14493}],"risk":0.14087499999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-93541","description":"A flaw was found in libXi. An out-of-bounds read vulnerability in the XQueryDeviceState() function allows a malicious X server to trigger an application crash. By returning a specially crafted response to a device state query, the server causes the client application to read memory beyond allocated buffer boundaries, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-93541","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93541","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93541","date":"2026-10-08","epss":0.00245,"percentile":0.14493}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=7b6fffd13fd3914e0b39f3a4f131913da7f066e7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93541","description":"An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a"}]},{"artifact":{"id":"579132f61ab96cf6","cpes":["cpe:2.3:a:redhat:libXi:1.7.10-8.el9:*:*:*:*:*:*:*","cpe:2.3:a:libXi:libXi:1.7.10-8.el9:*:*:*:*:*:*:*"],"name":"libXi","purl":"pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=rhel-9.8&upstream=libXi-1.7.10-8.el9.src.rpm","type":"rpm","version":"1.7.10-8.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-93544","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libXi","version":"0:1.7.10-8.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-93544","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93544","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93544","date":"2026-10-08","epss":0.00245,"percentile":0.14493}],"risk":0.14087499999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-93544","description":"A flaw was found in libXi. This out-of-bounds read vulnerability allows a malicious X server to cause a Denial of Service (DoS) against attached client applications. By returning a specially crafted response to an XIQueryDevice request, the server triggers an invalid memory read within the client, leading to an abnormal application crash."},"relatedVulnerabilities":[{"id":"CVE-2026-93544","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93544","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93544","date":"2026-10-08","epss":0.00245,"percentile":0.14493}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=a88a341135b79f6ed450f481e4a5d6ba502382af"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93544","description":"An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0992","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0992","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0992","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0992","date":"2026-10-08","epss":0.00465,"percentile":0.38301}],"risk":0.137175,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0992","description":"A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition."},"relatedVulnerabilities":[{"id":"CVE-2026-0992","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0992","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0992","date":"2026-10-08","epss":0.00465,"percentile":0.38301}],"urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0992","https://bugzilla.redhat.com/show_bug.cgi?id=2429975","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0992","description":"A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition."}]},{"artifact":{"id":"04d131149e28659d","cpes":["cpe:2.3:a:libXtst:libXtst:1.2.3-16.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libXtst:1.2.3-16.el9:*:*:*:*:*:*:*"],"name":"libXtst","purl":"pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=rhel-9.8&upstream=libXtst-1.2.3-16.el9.src.rpm","type":"rpm","version":"1.2.3-16.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-94286","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libXtst","version":"0:1.2.3-16.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-94286","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94286","cwe":"CWE-126","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94286","date":"2026-10-08","epss":0.00185,"percentile":0.0737}],"risk":0.13505,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-94286","description":"A flaw was found in libXtst. An out-of-bounds read vulnerability in the RECORD extension reply parser allows a malicious X server to cause a Denial of Service (DoS) by crashing connected client applications. Under certain conditions, this flaw may also result in limited information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-94286","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94286","cwe":"CWE-126","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94286","date":"2026-10-08","epss":0.00185,"percentile":0.0737}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxtst/-/merge_requests/10/diffs?commit_id=16023c86070e6af9407330deea3938fcef75815b"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94286","description":"An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41080","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-41080","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"risk":0.13333,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-41080","description":"A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing a specially crafted XML document that leverages insufficient entropy in the hash function. This can lead to hash flooding, a type of Denial of Service (DoS) attack, where the system becomes unresponsive or crashes due to excessive resource consumption."},"relatedVulnerabilities":[{"id":"CVE-2026-41080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"urls":["https://blog.hartwork.org/posts/expat-2-8-0-released/","https://github.com/libexpat/libexpat/issues/47","https://github.com/libexpat/libexpat/pull/1183","https://www.openwall.com/lists/oss-security/2026/04/26/1","http://www.openwall.com/lists/oss-security/2026/04/26/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-7039","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-7039","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7039","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-7039","date":"2026-10-08","epss":0.00397,"percentile":0.31786}],"risk":0.13299499999999997,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-7039","description":"A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations."},"relatedVulnerabilities":[{"id":"CVE-2025-7039","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7039","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-7039","date":"2026-10-08","epss":0.00397,"percentile":0.31786}],"urls":["https://access.redhat.com/security/cve/CVE-2025-7039","https://bugzilla.redhat.com/show_bug.cgi?id=2392423","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7039","description":"A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.132435,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77696","description":"A flaw was found in OpenSSL. During SM2 signature generation, variable-time arithmetic operations are performed on secret values, creating an observable timing side-channel. An attacker capable of measuring signature generation times can collect timing data across multiple signing operations, which may allow them to recover the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1757","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1757","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1757","cwe":"CWE-401","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1757","date":"2026-10-08","epss":0.00221,"percentile":0.11581}],"risk":0.12376000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1757","description":"A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system."},"relatedVulnerabilities":[{"id":"CVE-2026-1757","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1757","cwe":"CWE-401","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1757","date":"2026-10-08","epss":0.00221,"percentile":0.11581}],"urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-1757","https://bugzilla.redhat.com/show_bug.cgi?id=2435940","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1757","description":"A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84783","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84783","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84783","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84783","date":"2026-10-08","epss":0.00226,"percentile":0.12197}],"risk":0.12317,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84783","description":"A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by initiating concurrent connections to a multi-threaded Transport Layer Security (TLS) client or server verifying certificates. Due to improper synchronization when multiple threads simultaneously decode and cache certificate extensions for a shared Certificate Authority (CA) certificate, cached memory can be freed while still in use by another thread. This use-after-free condition results in an invalid memory read, causing the application to crash."},"relatedVulnerabilities":[{"id":"CVE-2026-84783","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84783","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84783","date":"2026-10-08","epss":0.00226,"percentile":0.12197}],"urls":["https://github.com/openssl/openssl/commit/de97a1a54f43edefd43b5084ecac54ecadb33081","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84783","description":"Issue summary: The first concurrent use of the same X.509 certificate by\nseveral threads may cause its cached extension data to be freed while\nanother thread is still using it.\n\nImpact summary: A remote, unauthenticated peer could crash a multi-threaded\nTLS client, or a multi-threaded TLS server that requests client\ncertificates, if the first certificate chains built to the same trusted CA\ncertificate are built by several connections at the same time. This is a\nuse-after-free read, which is likely to crash the process, resulting in a\nDenial of Service.\n\nCWE: CWE-416: Use After Free\n\nDescription: OpenSSL caches the decoded values of a certificate's X.509v3\nextensions inside the X509 object the first time they are needed. In\nOpenSSL 4.0 this cache is built in two phases: the extension values are\ncomputed while holding a read lock on the certificate, and the results are\nthen installed into the certificate under a write lock. Because a read lock\ndoes not exclude other readers, several threads can compute the cache for\nthe same certificate at the same time. Each thread that subsequently\nacquires the write lock installs its own results and frees the values\ninstalled by the thread before it, even though that earlier thread has\nalready marked the cache as complete and may have returned pointers into it\nto its caller. A caller still using those pointers then reads freed memory.\n\nAny certificate shared between threads is exposed the first time its\nextensions are decoded. In TLS the certificates at risk are the trusted CA\ncertificates supplied for chain verification, by whatever means, since these\nare shared by every connection and their extensions are decoded and cached\nthe first time a chain is built to them. Certificates sent by the peer are\ndecoded separately for each connection and are not shared, so they are not\naffected. In a TLS client verifying server certificates, or a TLS server\nthat requests and verifies client certificates, the use-after-free could\nonly occur if the first chains built to the same trusted CA are built by\nseveral connections at the same time.\n\nFIPS impact: no\nThe FIPS module is not affected as X.509 certificate handling is outside\nof the OpenSSL FIPS module boundary.\n\nOpenSSL 4.0 is vulnerable to this issue.\n\nOpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\n\nThis issue was reported on 27 August 2026 by Tim Becker (Xint.io) and\nindependently in a public report on 31 August 2026 by aydinmercan.\n\nThe fix has been developed by Bob Beck.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Tim Becker (Xint.io), aydinmercan\nFixed by: Bob Beck"}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89092","description":"A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, causing it to crash and leading to degraded DNS resolution for the system. There is also a remote possibility of nscd cache corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89092","description":"A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, causing it to crash and leading to degraded DNS resolution for the system. There is also a remote possibility of nscd cache corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89092","description":"A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, causing it to crash and leading to degraded DNS resolution for the system. There is also a remote possibility of nscd cache corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-13837","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-13837","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13837","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13837","date":"2026-10-08","epss":0.00223,"percentile":0.11847}],"risk":0.12153500000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-13837","description":"A flaw was found in the plistlib module in the Python standard library. The amount of data to read from a Plist file is specified in the file itself. This issue allows a specially crafted Plist file to cause an application to allocate a large amount of memory, potentially resulting in allocations errors, swapping, out-of-memory conditions or even system freezes."},"relatedVulnerabilities":[{"id":"CVE-2025-13837","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13837","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13837","date":"2026-10-08","epss":0.00223,"percentile":0.11847}],"urls":["https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036","https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2b","https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70","https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba","https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb","https://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111","https://github.com/python/cpython/issues/119342","https://github.com/python/cpython/pull/119343","https://mail.python.org/archives/list/security-announce@python.org/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13837","description":"When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues"}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-13837","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-13837","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13837","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13837","date":"2026-10-08","epss":0.00223,"percentile":0.11847}],"risk":0.12153500000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-13837","description":"A flaw was found in the plistlib module in the Python standard library. The amount of data to read from a Plist file is specified in the file itself. This issue allows a specially crafted Plist file to cause an application to allocate a large amount of memory, potentially resulting in allocations errors, swapping, out-of-memory conditions or even system freezes."},"relatedVulnerabilities":[{"id":"CVE-2025-13837","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13837","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13837","date":"2026-10-08","epss":0.00223,"percentile":0.11847}],"urls":["https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036","https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2b","https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70","https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba","https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb","https://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111","https://github.com/python/cpython/issues/119342","https://github.com/python/cpython/pull/119343","https://mail.python.org/archives/list/security-announce@python.org/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13837","description":"When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues"}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.12099000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75805","description":"A flaw was found in OpenSSL. When a Certificate Management Protocol (CMP) client requests certificate revocation using a PKCS#10 Certificate Signing Request (CSR), it omits the certificate issuer name and serial number. A malicious or compromised CMP server, or an attacker possessing valid message protection credentials, can exploit this flaw by returning a crafted revocation response. This triggers a NULL pointer dereference when the client attempts to compare response data, causing the client application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.11990000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6791","description":"A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.11990000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6791","description":"A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.11990000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6791","description":"A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-35191","description":"A flaw was found in OpenSSL. This vulnerability allows a remote attacker to abuse the server to amplify network traffic in a Denial of Service (DoS) attack. When the server is configured without client address validation, incoming datagrams containing multiple QUIC packets cause the server to calculate credit limits incorrectly by adding the total datagram size for each packet. Consequently, the server exceeds standard rate limits and transmits excessive response data to spoofed target addresses."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.13-14.el9_8.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86140","versionConstraint":"< 0:2.9.13-14.el9_8.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86140","fix":{"state":"fixed","versions":["0:2.9.13-14.el9_8.5"],"available":[{"date":"2026-09-25","kind":"first-observed","version":"0:2.9.13-14.el9_8.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.116965,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:71585","link":"https://access.redhat.com/errata/RHSA-2026:71585"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86140","description":"A flaw was found in libxml2. A local attacker could exploit a stack-based buffer overflow in the `xmlSnprintfElements` function to achieve arbitrary code execution. This vulnerability in a fundamental system library could lead to significant system compromise if successfully exploited."},"relatedVulnerabilities":[{"id":"CVE-2026-86140","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86140","description":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.13-14.el9_8.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86143","versionConstraint":"< 0:2.9.13-14.el9_8.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86143","fix":{"state":"fixed","versions":["0:2.9.13-14.el9_8.5"],"available":[{"date":"2026-09-25","kind":"first-observed","version":"0:2.9.13-14.el9_8.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"risk":0.11543,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:71585","link":"https://access.redhat.com/errata/RHSA-2026:71585"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86143","description":"An integer overflow in the libxml2 xmlIO module occurs when data backlogs exceed maximum integer limits. This flaw passes negative length values to downstream write callbacks, creating an unsafe state that can lead to data corruption or compromise application confidentiality and integrity."},"relatedVulnerabilities":[{"id":"CVE-2026-86143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"urls":["https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86143","description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback."}]},{"artifact":{"id":"579132f61ab96cf6","cpes":["cpe:2.3:a:redhat:libXi:1.7.10-8.el9:*:*:*:*:*:*:*","cpe:2.3:a:libXi:libXi:1.7.10-8.el9:*:*:*:*:*:*:*"],"name":"libXi","purl":"pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=rhel-9.8&upstream=libXi-1.7.10-8.el9.src.rpm","type":"rpm","version":"1.7.10-8.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-93545","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libXi","version":"0:1.7.10-8.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-93545","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93545","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93545","date":"2026-10-08","epss":0.00199,"percentile":0.08918}],"risk":0.11442499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-93545","description":"A flaw was found in libXi. An out-of-bounds read vulnerability in the XListInputDevices() function allows a malicious X server to crash connected client applications. By returning specially crafted input device data when a client requests device information, the server can trigger an application crash, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-93545","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93545","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-93545","date":"2026-10-08","epss":0.00199,"percentile":0.08918}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=234ce17d95c42d75f7f7fdb2bf7a24875451bc0a"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93545","description":"An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client."}]},{"artifact":{"id":"bb1caebf00bfd67f","cpes":["cpe:2.3:a:libX11:libX11:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11","purl":"pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-94283","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"0:1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-94283","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"risk":0.11442499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-94283","description":"A flaw was found in libX11. An out-of-bounds read vulnerability in the X Input Method (XIM) attribute parser allows a malicious X server to cause a Denial of Service (DoS) by crashing connected client applications when processing specially crafted attributes."},"relatedVulnerabilities":[{"id":"CVE-2026-94283","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"6a1cd4ae8b36edce","cpes":["cpe:2.3:a:libX11-common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11-common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11-common","purl":"pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libX11","version":"1.8.12-1.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94283","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-94283","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"risk":0.11442499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-94283","description":"A flaw was found in libX11. An out-of-bounds read vulnerability in the X Input Method (XIM) attribute parser allows a malicious X server to cause a Denial of Service (DoS) by crashing connected client applications when processing specially crafted attributes."},"relatedVulnerabilities":[{"id":"CVE-2026-94283","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"579132f61ab96cf6","cpes":["cpe:2.3:a:redhat:libXi:1.7.10-8.el9:*:*:*:*:*:*:*","cpe:2.3:a:libXi:libXi:1.7.10-8.el9:*:*:*:*:*:*:*"],"name":"libXi","purl":"pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=rhel-9.8&upstream=libXi-1.7.10-8.el9.src.rpm","type":"rpm","version":"1.7.10-8.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-94281","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libXi","version":"0:1.7.10-8.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-94281","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94281","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94281","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"risk":0.11442499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-94281","description":"A flaw was found in libXi. An out-of-bounds read vulnerability exists in the XListInputDevices() function during the parsing of input device classes. A malicious X server can exploit this flaw by returning crafted device information, causing an attached X client application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-94281","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94281","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94281","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=605f419d013153bf9e026cd100752ffbe930f3c1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94281","description":"An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client."}]},{"artifact":{"id":"448588eb4147df6f","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-343h-94h5-c4wr","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-343h-94h5-c4wr","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"risk":0.11356499999999997,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","https://nvd.nist.gov/vuln/detail/CVE-2026-106449","https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-343h-94h5-c4wr","description":"yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError"},"relatedVulnerabilities":[{"id":"CVE-2026-106449","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"urls":["https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"9d4b5e84721dd1cf","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/lz4-java-1.11.1.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-343h-94h5-c4wr","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-343h-94h5-c4wr","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"risk":0.11356499999999997,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","https://nvd.nist.gov/vuln/detail/CVE-2026-106449","https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-343h-94h5-c4wr","description":"yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError"},"relatedVulnerabilities":[{"id":"CVE-2026-106449","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"urls":["https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"9356f22b5dfd0bcd","cpes":["cpe:2.3:a:alsa-lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=rhel-9.8&upstream=alsa-lib-1.2.15.3-1.el9.src.rpm","type":"rpm","version":"1.2.15.3-1.el9","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56109","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"alsa-lib","version":"0:1.2.15.3-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56109","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56109","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56109","date":"2026-10-08","epss":0.00186,"percentile":0.07489}],"risk":0.10974,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56109","description":"A flaw was found in the ALSA (Advanced Linux Sound Architecture) library. This double-free vulnerability, located in the `parse_def()` function, allows a local attacker to corrupt memory by providing specially crafted ALSA configuration text. When processing nested configuration blocks, the library attempts to free an already freed memory node. This can lead to system instability, crashes, or a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-56109","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56109","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56109","date":"2026-10-08","epss":0.00186,"percentile":0.07489}],"urls":["https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0","https://github.com/alsa-project/alsa-lib/releases/tag/v1.2.16.1","https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/","https://www.vulncheck.com/advisories/alsa-library-double-free-via-parse-def-in-conf-c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56109","description":"The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4516","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-4516","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.1,"impactScore":3.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4516","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4516","date":"2026-10-08","epss":0.00216,"percentile":0.11028}],"risk":0.10908000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4516","description":"A vulnerability has been identified in CPython's bytes.decode() function when used with the \"unicode_escape\" encoding and the \"ignore\" or \"replace\" error handling modes. This flaw can result in the incorrect decoding of byte strings. While this may not directly lead to traditional security breaches like data exfiltration, the resulting unexpected program behavior could introduce instability, logic errors, or unintended side effects within applications that rely on this specific decoding functionality."},"relatedVulnerabilities":[{"id":"CVE-2025-4516","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4516","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4516","date":"2026-10-08","epss":0.00216,"percentile":0.11028}],"urls":["https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292","https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d","https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142","https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f","https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77","https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e","https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b","https://github.com/python/cpython/issues/133767","https://github.com/python/cpython/pull/129648","https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/","http://www.openwall.com/lists/oss-security/2025/05/16/4","http://www.openwall.com/lists/oss-security/2025/05/19/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4516","description":"There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4516","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-4516","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.1,"impactScore":3.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4516","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4516","date":"2026-10-08","epss":0.00216,"percentile":0.11028}],"risk":0.10908000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4516","description":"A vulnerability has been identified in CPython's bytes.decode() function when used with the \"unicode_escape\" encoding and the \"ignore\" or \"replace\" error handling modes. This flaw can result in the incorrect decoding of byte strings. While this may not directly lead to traditional security breaches like data exfiltration, the resulting unexpected program behavior could introduce instability, logic errors, or unintended side effects within applications that rely on this specific decoding functionality."},"relatedVulnerabilities":[{"id":"CVE-2025-4516","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4516","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4516","date":"2026-10-08","epss":0.00216,"percentile":0.11028}],"urls":["https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292","https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d","https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142","https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f","https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77","https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e","https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b","https://github.com/python/cpython/issues/133767","https://github.com/python/cpython/pull/129648","https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/","http://www.openwall.com/lists/oss-security/2025/05/16/4","http://www.openwall.com/lists/oss-security/2025/05/19/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4516","description":"There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":3.4,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.10396,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19542","description":"A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":3.4,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.10396,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19542","description":"A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":3.4,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.10396,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19542","description":"A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56406","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56406","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56406","date":"2026-10-08","epss":0.00174,"percentile":0.06239}],"risk":0.10353000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56406","description":"A flaw was found in libexpat. An integer overflow vulnerability exists in the `XML_ParseBuffer` function due to a missing check. This flaw could allow an attacker to cause memory corruption, potentially leading to arbitrary code execution, information disclosure, or a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-56406","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56406","date":"2026-10-08","epss":0.00174,"percentile":0.06239}],"urls":["https://github.com/libexpat/libexpat/pull/1255"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56406","description":"libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56407","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56407","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56407","date":"2026-10-08","epss":0.00174,"percentile":0.06239}],"risk":0.10353000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56407","description":"An integer overflow exists in libexpat's doProlog function due to improper handling of entity value lengths. A local attacker could exploit this to execute arbitrary code or access sensitive system data."},"relatedVulnerabilities":[{"id":"CVE-2026-56407","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56407","date":"2026-10-08","epss":0.00174,"percentile":0.06239}],"urls":["https://github.com/libexpat/libexpat/pull/1262"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56407","description":"libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.10169999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-12345","description":"A flaw was found in Python. A race condition during the cleanup of temporary directories allows a local attacker with write access to replace a directory with a symbolic link (a reference pointing to another location). This can lead to unauthorized deletion or alteration of files outside the temporary directory, performed with the privileges of the process executing the cleanup."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.10169999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-12345","description":"A flaw was found in Python. A race condition during the cleanup of temporary directories allows a local attacker with write access to replace a directory with a symbolic link (a reference pointing to another location). This can lead to unauthorized deletion or alteration of files outside the temporary directory, performed with the privileges of the process executing the cleanup."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"aff0baca8a045287","cpes":["cpe:2.3:a:libblkid:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libblkid","purl":"pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"66ba386a85828620","cpes":["cpe:2.3:a:libmount:libmount:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libmount:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libmount","purl":"pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"63e8f89642ab1486","cpes":["cpe:2.3:a:libuuid:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libuuid","purl":"pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.13-14.el9_8.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86144","versionConstraint":"< 0:2.9.13-14.el9_8.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86144","fix":{"state":"fixed","versions":["0:2.9.13-14.el9_8.5"],"available":[{"date":"2026-09-25","kind":"first-observed","version":"0:2.9.13-14.el9_8.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"risk":0.09858,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:71585","link":"https://access.redhat.com/errata/RHSA-2026:71585"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86144","description":"A flaw in libxml2's XInclude processing (xmlXIncludeProcess and xmlXIncludeProcessTree) fails to propagate parser flags like XML_PARSE_NONET. This allows custom resource loaders to fetch external network resources, potentially enabling Server-Side Request Forgery (SSRF), XML External Entity (XXE) injection, or Denial of Service (DoS) attacks."},"relatedVulnerabilities":[{"id":"CVE-2026-86144","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"urls":["https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86144","description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-97399","description":"A flaw was found in glibc. In builds optimized for specific hardware architectures, the string comparison function strncasecmp may read one byte beyond the boundary of the provided input string. An attacker capable of passing controlled strings that end at the edge of a memory page could trigger an invalid memory access and crash the application, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-97399","description":"A flaw was found in glibc. In builds optimized for specific hardware architectures, the string comparison function strncasecmp may read one byte beyond the boundary of the provided input string. An attacker capable of passing controlled strings that end at the edge of a memory page could trigger an invalid memory access and crash the application, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-97399","description":"A flaw was found in glibc. In builds optimized for specific hardware architectures, the string comparison function strncasecmp may read one byte beyond the boundary of the provided input string. An attacker capable of passing controlled strings that end at the edge of a memory page could trigger an invalid memory access and crash the application, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"c199e35d680b31d4","cpes":["cpe:2.3:a:coreutils:coreutils:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:coreutils:8.32-41.el9_8:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:rpm/redhat/coreutils@8.32-41.el9_8?arch=x86_64&distro=rhel-9.8&upstream=coreutils-8.32-41.el9_8.src.rpm","type":"rpm","version":"8.32-41.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56391","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"coreutils","version":"0:8.32-41.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.09490499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56391","description":"A flaw was found in GNU coreutils uniq. When processing specially crafted multibyte input with the --check-chars option, an attacker can trigger an out-of-bounds read. This vulnerability can lead to a denial of service (DoS) due to an application crash and potentially expose sensitive information from adjacent memory."},"relatedVulnerabilities":[{"id":"CVE-2026-56391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."}]},{"artifact":{"id":"325861d10db0a55f","cpes":["cpe:2.3:a:coreutils-common:coreutils-common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-common:coreutils_common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_common:coreutils-common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_common:coreutils_common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:coreutils-common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:coreutils_common:8.32-41.el9_8:*:*:*:*:*:*:*"],"name":"coreutils-common","purl":"pkg:rpm/redhat/coreutils-common@8.32-41.el9_8?arch=x86_64&distro=rhel-9.8&upstream=coreutils-8.32-41.el9_8.src.rpm","type":"rpm","version":"8.32-41.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils","version":"8.32-41.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56391","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"coreutils","version":"8.32-41.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.09490499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56391","description":"A flaw was found in GNU coreutils uniq. When processing specially crafted multibyte input with the --check-chars option, an attacker can trigger an out-of-bounds read. This vulnerability can lead to a denial of service (DoS) due to an application crash and potentially expose sensitive information from adjacent memory."},"relatedVulnerabilities":[{"id":"CVE-2026-56391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."}]},{"artifact":{"id":"1c9a349fe96f859f","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=sqlite-3.34.1-11.el9_8.src.rpm","type":"rpm","version":"3.34.1-11.el9_8","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.34.1-11.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-70873","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"sqlite","version":"3.34.1-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-70873","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-70873","date":"2026-10-08","epss":0.00301,"percentile":0.20911}],"risk":0.09481499999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-70873","description":"A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile extension, specifically in the zipfileInflate function. A remote attacker could exploit this by providing a specially crafted ZIP file. Successful exploitation could lead to the disclosure of sensitive heap memory information."},"relatedVulnerabilities":[{"id":"CVE-2025-70873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-70873","date":"2026-10-08","epss":0.00301,"percentile":0.20911}],"urls":["https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054","https://sqlite.org/forum/forumpost/761eac3c82","https://sqlite.org/src/info/3d459f1fb1bd1b5e"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-70873","description":"An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file."}]},{"artifact":{"id":"9356f22b5dfd0bcd","cpes":["cpe:2.3:a:alsa-lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=rhel-9.8&upstream=alsa-lib-1.2.15.3-1.el9.src.rpm","type":"rpm","version":"1.2.15.3-1.el9","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90781","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"alsa-lib","version":"0:1.2.15.3-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-90781","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90781","cwe":"CWE-193","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-90781","date":"2026-10-08","epss":0.0017,"percentile":0.0582}],"risk":0.09434999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-90781","description":"A flaw was found in alsa-lib. This vulnerability is an off-by-one stack buffer overflow in the `__snd_ctl_ascii_elem_id_parse()` function. A local attacker can exploit this by supplying a specially crafted, long control-element identifier string through saved state files or command-line arguments. This can cause the application to write one byte past a 64-byte buffer, leading to adjacent stack memory corruption and a crash of the calling process, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-90781","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90781","cwe":"CWE-193","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-90781","date":"2026-10-08","epss":0.0017,"percentile":0.0582}],"urls":["https://github.com/alsa-project/alsa-lib","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241","https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020","https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/","https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90781","description":"alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.09387,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89161","description":"A flaw was found in PCRE2, a library for processing regular expressions. The `pcre2_jit_match` function, which handles just-in-time (JIT) compilation for regular expressions, incorrectly manages memory when processing certain inputs. This memory corruption vulnerability could allow a local attacker to cause the application to crash, leading to a denial of service, or potentially execute unauthorized code."},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.09387,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89161","description":"A flaw was found in PCRE2, a library for processing regular expressions. The `pcre2_jit_match` function, which handles just-in-time (JIT) compilation for regular expressions, incorrectly manages memory when processing certain inputs. This memory corruption vulnerability could allow a local attacker to cause the application to crash, leading to a denial of service, or potentially execute unauthorized code."},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.13-14.el9_8.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86142","versionConstraint":"< 0:2.9.13-14.el9_8.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86142","fix":{"state":"fixed","versions":["0:2.9.13-14.el9_8.5"],"available":[{"date":"2026-09-25","kind":"first-observed","version":"0:2.9.13-14.el9_8.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"risk":0.093415,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:71585","link":"https://access.redhat.com/errata/RHSA-2026:71585"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86142","description":"A flaw in libxml2's xmlXPtrEvalXPtrPart function allows a local attacker to cause a heap-based buffer overflow. An integer overflow while processing an oversized xpointer() expression leads to incorrect memory allocation and an out-of-bounds write, potentially resulting in information disclosure, data corruption, or a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-86142","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"urls":["https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86142","description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation."}]},{"artifact":{"id":"9356f22b5dfd0bcd","cpes":["cpe:2.3:a:alsa-lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=rhel-9.8&upstream=alsa-lib-1.2.15.3-1.el9.src.rpm","type":"rpm","version":"1.2.15.3-1.el9","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25068","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"alsa-lib","version":"0:1.2.15.3-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-25068","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25068","cwe":"CWE-129","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-25068","date":"2026-10-08","epss":0.00198,"percentile":0.08831}],"risk":0.09206999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-25068","description":"alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash."},"relatedVulnerabilities":[{"id":"CVE-2026-25068","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25068","cwe":"CWE-129","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-25068","date":"2026-10-08","epss":0.00198,"percentile":0.08831}],"urls":["https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40","https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow","https://lists.debian.org/debian-lts-announce/2026/02/msg00008.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25068","description":"alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash."}]},{"artifact":{"id":"2e7650523e20cfd7","cpes":["cpe:2.3:a:freetype:freetype:2.10.4-10.el9_5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:freetype:2.10.4-10.el9_5:*:*:*:*:*:*:*"],"name":"freetype","purl":"pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=rhel-9.8&upstream=freetype-2.10.4-10.el9_5.src.rpm","type":"rpm","version":"2.10.4-10.el9_5","language":"","licenses":["(FTL or GPLv2+) and BSD and MIT and Public Domain and zlib with acknowledgement"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95512","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"freetype","version":"0:2.10.4-10.el9_5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95512","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"risk":0.09135,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95512","description":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate."},"relatedVulnerabilities":[{"id":"CVE-2026-95512","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"urls":["https://access.redhat.com/errata/RHSA-2026:74952","https://access.redhat.com/security/cve/CVE-2026-95512","https://bugzilla.redhat.com/show_bug.cgi?id=2462295","https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95512","description":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate."}]},{"artifact":{"id":"6c6ff44b2d10b255","cpes":["cpe:2.3:a:bzip2-libs:bzip2-libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2-libs:bzip2_libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2_libs:bzip2-libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2_libs:bzip2_libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:bzip2-libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:bzip2_libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2:bzip2-libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2:bzip2_libs:1.0.8-11.el9:*:*:*:*:*:*:*"],"name":"bzip2-libs","purl":"pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=rhel-9.8&upstream=bzip2-1.0.8-11.el9.src.rpm","type":"rpm","version":"1.0.8-11.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"bzip2","version":"1.0.8-11.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"bzip2","version":"1.0.8-11.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42250","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42250","description":"A flaw was found in bzip2. The bzip2recover utility contains an off-by-one error that allows a local attacker to cause an out-of-bounds write to a global buffer by processing a specially crafted file. This memory corruption can lead to a crash, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-42250","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"}]},{"artifact":{"id":"a6c320bbdb2151ba","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=libpng-1.6.37-15.el9_8.2.src.rpm","type":"rpm","version":"2:1.6.37-15.el9_8.2","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-64505","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libpng","version":"2:1.6.37-15.el9_8.2"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-64505","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64505","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64505","date":"2026-10-08","epss":0.00192,"percentile":0.08077}],"risk":0.09024,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-64505","description":"A heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access."},"relatedVulnerabilities":[{"id":"CVE-2025-64505","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64505","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64505","date":"2026-10-08","epss":0.00192,"percentile":0.08077}],"urls":["https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37","https://github.com/pnggroup/libpng/pull/748","https://github.com/pnggroup/libpng/security/advisories/GHSA-4952-h5wq-4m42"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-64505","description":"LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.08978,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89160","description":"A flaw was found in PCRE2, a library for processing regular expressions. A remote attacker could exploit this vulnerability by providing a specially crafted input that triggers an out-of-bounds read during pattern matching with invalid UTF (Unicode Transformation Format) characters. This could lead to a denial of service, making the affected system or application unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.08978,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89160","description":"A flaw was found in PCRE2, a library for processing regular expressions. A remote attacker could exploit this vulnerability by providing a specially crafted input that triggers an out-of-bounds read during pattern matching with invalid UTF (Unicode Transformation Format) characters. This could lead to a denial of service, making the affected system or application unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"1c27b1fc065b3d30","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:21.3.1-2.el9_8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=rhel-9.8&upstream=python-pip-21.3.1-2.el9_8.src.rpm","type":"rpm","version":"21.3.1-2.el9_8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"21.3.1-2.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25645","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python-pip","version":"21.3.1-2.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-25645","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25645","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25645","date":"2026-10-08","epss":0.00185,"percentile":0.07433}],"risk":0.089725,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-25645","description":"A flaw was found in the `requests` HTTP library, specifically in the `requests.utils.extract_zipped_paths()` function, which is used to load Certificate Authority (CA) bundles. A local attacker can exploit this vulnerability by pre-creating a malicious CA bundle file in the system's temporary directory. When a vulnerable application initializes the `requests` library, it may load this malicious file instead of the legitimate CA bundle, leading to a bypass of security controls and potential integrity compromise."},"relatedVulnerabilities":[{"id":"CVE-2026-25645","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25645","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25645","date":"2026-10-08","epss":0.00185,"percentile":0.07433}],"urls":["https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7","https://github.com/psf/requests/releases/tag/v2.33.0","https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25645","description":"Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.089445,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-35189","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by presenting a specially crafted certificate during a Transport Layer Security (TLS) handshake. When OpenSSL processes and caches certificate extensions containing numerous Certificate Revocation List (CRL) distribution points, it allocates an excessive amount of memory. This disproportionate memory usage can exhaust system resources and crash the affected client or server application."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42308","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42308","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42308","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42308","date":"2026-10-08","epss":0.00159,"percentile":0.04419}],"risk":0.08904000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42308","description":"A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condition, making the application unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-42308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42308","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42308","date":"2026-10-08","epss":0.00159,"percentile":0.04419}],"urls":["https://github.com/python-pillow/Pillow/releases/tag/12.2.0","https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42308","description":"Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42308","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42308","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42308","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42308","date":"2026-10-08","epss":0.00159,"percentile":0.04419}],"risk":0.08904000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42308","description":"A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condition, making the application unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-42308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42308","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42308","date":"2026-10-08","epss":0.00159,"percentile":0.04419}],"urls":["https://github.com/python-pillow/Pillow/releases/tag/12.2.0","https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42308","description":"Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-32776","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-32776","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32776","date":"2026-10-08","epss":0.00159,"percentile":0.04405}],"risk":0.08904000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-32776","description":"A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted XML content with empty external parameter entities. This could lead to a NULL pointer dereference, causing the application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-32776","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32776","date":"2026-10-08","epss":0.00159,"percentile":0.04405}],"urls":["https://github.com/libexpat/libexpat/pull/1158","https://github.com/libexpat/libexpat/pull/1159","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32776","description":"libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56412","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56412","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56412","date":"2026-10-08","epss":0.00179,"percentile":0.06808}],"risk":0.088605,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56412","description":"A flaw was found in libexpat. This vulnerability, present in versions before 2.8.2, stems from improper handling of XML CDATA sections, where the library fails to adequately track the depth of handler calls. This can result in a 'use-after-free' error, a type of memory corruption that could allow an attacker to crash the application or potentially gain unauthorized control."},"relatedVulnerabilities":[{"id":"CVE-2026-56412","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"impactScore":3.4,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56412","date":"2026-10-08","epss":0.00179,"percentile":0.06808}],"urls":["https://github.com/libexpat/libexpat/pull/1278"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56412","description":"libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219."}]},{"artifact":{"id":"c199e35d680b31d4","cpes":["cpe:2.3:a:coreutils:coreutils:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:coreutils:8.32-41.el9_8:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:rpm/redhat/coreutils@8.32-41.el9_8?arch=x86_64&distro=rhel-9.8&upstream=coreutils-8.32-41.el9_8.src.rpm","type":"rpm","version":"8.32-41.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:8.32-41.el9_8.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56392","versionConstraint":"< 0:8.32-41.el9_8.1 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"coreutils","version":"0:8.32-41.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"fixed","versions":["0:8.32-41.el9_8.1"],"available":[{"date":"2026-09-11","kind":"first-observed","version":"0:8.32-41.el9_8.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.08742000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:66403","link":"https://access.redhat.com/errata/RHSA-2026:66403"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56392","description":"A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when `unexpand` processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation."},"relatedVulnerabilities":[{"id":"CVE-2026-56392","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"}]},{"artifact":{"id":"325861d10db0a55f","cpes":["cpe:2.3:a:coreutils-common:coreutils-common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-common:coreutils_common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_common:coreutils-common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_common:coreutils_common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:coreutils-common:8.32-41.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:coreutils_common:8.32-41.el9_8:*:*:*:*:*:*:*"],"name":"coreutils-common","purl":"pkg:rpm/redhat/coreutils-common@8.32-41.el9_8?arch=x86_64&distro=rhel-9.8&upstream=coreutils-8.32-41.el9_8.src.rpm","type":"rpm","version":"8.32-41.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils","version":"8.32-41.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:8.32-41.el9_8.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56392","versionConstraint":"< 0:8.32-41.el9_8.1 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"coreutils","version":"8.32-41.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"fixed","versions":["0:8.32-41.el9_8.1"],"available":[{"date":"2026-09-11","kind":"first-observed","version":"0:8.32-41.el9_8.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.08742000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:66403","link":"https://access.redhat.com/errata/RHSA-2026:66403"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56392","description":"A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when `unexpand` processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation."},"relatedVulnerabilities":[{"id":"CVE-2026-56392","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"}]},{"artifact":{"id":"556252d270ab3c54","cpes":["cpe:2.3:a:systemd-libs:systemd-libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd-libs:systemd_libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd-libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd_libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_libs:252-67.el9_8.4:*:*:*:*:*:*:*"],"name":"systemd-libs","purl":"pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=systemd-252-67.el9_8.4.src.rpm","type":"rpm","version":"252-67.el9_8.4","language":"","licenses":["LGPLv2+ and MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"252-67.el9_8.4"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4105","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"252-67.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4105","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"risk":0.08716499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."},"relatedVulnerabilities":[{"id":"CVE-2026-4105","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"urls":["https://access.redhat.com/errata/RHSA-2026:7299","https://access.redhat.com/security/cve/CVE-2026-4105","https://bugzilla.redhat.com/show_bug.cgi?id=2447262","https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.08672999999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89156","description":"A flaw was found in PCRE2. An attacker can provide invalid UTF (Unicode Transformation Format) data, leading to an out-of-bounds read during a Just-In-Time (JIT) fallback. This vulnerability could potentially result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.08672999999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89156","description":"A flaw was found in PCRE2. An attacker can provide invalid UTF (Unicode Transformation Format) data, leading to an out-of-bounds read during a Just-In-Time (JIT) fallback. This vulnerability could potentially result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5713","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-5713","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6,"impactScore":5.2,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5713","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-5713","cwe":"CWE-125","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-5713","date":"2026-10-08","epss":0.00153,"percentile":0.039}],"risk":0.08415,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5713","description":"A flaw was found in Python. A malicious Python process could exploit the \"profiling.sampling\" module and \"asyncio introspection capabilities\" to read and write memory addresses within a privileged process. This vulnerability occurs when the privileged process connects to the malicious process via its remote debugging feature, potentially leading to information disclosure and arbitrary code execution. Successful exploitation requires repeated connections, which may cause instability in the connecting process."},"relatedVulnerabilities":[{"id":"CVE-2026-5713","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5713","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-5713","cwe":"CWE-125","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-5713","date":"2026-10-08","epss":0.00153,"percentile":0.039}],"urls":["https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67","https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d","https://github.com/python/cpython/issues/148178","https://github.com/python/cpython/pull/148187","https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/","http://www.openwall.com/lists/oss-security/2026/04/15/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5713","description":"The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5713","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-5713","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6,"impactScore":5.2,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5713","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-5713","cwe":"CWE-125","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-5713","date":"2026-10-08","epss":0.00153,"percentile":0.039}],"risk":0.08415,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5713","description":"A flaw was found in Python. A malicious Python process could exploit the \"profiling.sampling\" module and \"asyncio introspection capabilities\" to read and write memory addresses within a privileged process. This vulnerability occurs when the privileged process connects to the malicious process via its remote debugging feature, potentially leading to information disclosure and arbitrary code execution. Successful exploitation requires repeated connections, which may cause instability in the connecting process."},"relatedVulnerabilities":[{"id":"CVE-2026-5713","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5713","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-5713","cwe":"CWE-125","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-5713","date":"2026-10-08","epss":0.00153,"percentile":0.039}],"urls":["https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67","https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d","https://github.com/python/cpython/issues/148178","https://github.com/python/cpython/pull/148187","https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/","http://www.openwall.com/lists/oss-security/2026/04/15/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5713","description":"The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR."}]},{"artifact":{"id":"1c9a349fe96f859f","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=sqlite-3.34.1-11.el9_8.src.rpm","type":"rpm","version":"3.34.1-11.el9_8","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.34.1-11.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-50812","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"sqlite","version":"3.34.1-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-50812","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-08","epss":0.0016,"percentile":0.04607}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-50812","description":"A flaw was found in SQLite. The Session Extension in SQLite is vulnerable to a NULL pointer dereference. A remote attacker could exploit this by supplying a specially crafted, malformed changeset blob. This could lead to a denial of service, making the application unavailable to legitimate users."},"relatedVulnerabilities":[{"id":"CVE-2026-50812","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-08","epss":0.0016,"percentile":0.04607}],"urls":["https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91","https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d","https://sqlite.org/src/info/e807d4e3798efd53"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50812","description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer."}]},{"artifact":{"id":"556252d270ab3c54","cpes":["cpe:2.3:a:systemd-libs:systemd-libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd-libs:systemd_libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd-libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd_libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-libs:252-67.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_libs:252-67.el9_8.4:*:*:*:*:*:*:*"],"name":"systemd-libs","purl":"pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=systemd-252-67.el9_8.4.src.rpm","type":"rpm","version":"252-67.el9_8.4","language":"","licenses":["LGPLv2+ and MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"252-67.el9_8.4"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"252-67.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15059","description":"A flaw was found in systemd-oomd. Local unprivileged users can exploit a missing path traversal validation in the systemd-oomd Inter-Process Communication (IPC) Application Programming Interface (API). This vulnerability allows them to terminate arbitrary local processes, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56131","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56131","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.5,"impactScore":3.4,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56131","date":"2026-10-08","epss":0.00175,"percentile":0.06422}],"risk":0.08312499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56131","description":"A use-after-free vulnerability in libexpat occurs because handler call depth isn't properly tracked when XML_ResumeParser is invoked during policy violations. This flaw can lead to information disclosure, data corruption, or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-56131","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56131","date":"2026-10-08","epss":0.00175,"percentile":0.06422}],"urls":["https://github.com/libexpat/libexpat/pull/1267"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56131","description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation)."}]},{"artifact":{"id":"a6c320bbdb2151ba","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=libpng-1.6.37-15.el9_8.2.src.rpm","type":"rpm","version":"2:1.6.37-15.el9_8.2","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-28164","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libpng","version":"2:1.6.37-15.el9_8.2"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-28164","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-28164","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-28164","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-28164","date":"2026-10-08","epss":0.00162,"percentile":0.04879}],"risk":0.08099999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-28164","description":"A flaw was found in libpng. This buffer overflow vulnerability allows a local attacker to cause a denial of service (DoS) by exploiting the `png_create_read_struct()` function. This can lead to the affected system becoming unresponsive or crashing."},"relatedVulnerabilities":[{"id":"CVE-2025-28164","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-28164","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-28164","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-28164","date":"2026-10-08","epss":0.00162,"percentile":0.04879}],"urls":["https://gist.github.com/kittener/506516f8c22178005b4379c8b2a7de20","https://github.com/pnggroup/libpng/issues/655"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-28164","description":"Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-32778","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-32778","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.1,"impactScore":3.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32778","date":"2026-10-08","epss":0.00157,"percentile":0.04243}],"risk":0.079285,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-32778","description":"A flaw was found in libexpat. This vulnerability allows an attacker to trigger a NULL pointer dereference in the `setContext` function. This occurs when the system attempts to retry an operation after an out-of-memory condition, which can lead to a Denial of Service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-32778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32778","date":"2026-10-08","epss":0.00157,"percentile":0.04243}],"urls":["https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1163","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32778","description":"libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition."}]},{"artifact":{"id":"1306d3b83a8d37c1","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.4:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.4.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.4","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.13-14.el9_8.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86138","versionConstraint":"< 0:2.9.13-14.el9_8.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.4"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86138","fix":{"state":"fixed","versions":["0:2.9.13-14.el9_8.5"],"available":[{"date":"2026-09-25","kind":"first-observed","version":"0:2.9.13-14.el9_8.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"risk":0.07854,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:71585","link":"https://access.redhat.com/errata/RHSA-2026:71585"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86138","description":"A flaw was found in libxml2, a software library for parsing XML documents. An integer overflow within the `xmlDictAddQString` function can lead to a heap-based buffer overflow. This vulnerability could allow a local attacker to execute arbitrary code on the system, potentially compromising its integrity and confidentiality."},"relatedVulnerabilities":[{"id":"CVE-2026-86138","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"urls":["https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86138","description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-32777","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-32777","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32777","date":"2026-10-08","epss":0.00174,"percentile":0.06263}],"risk":0.07830000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-32777","description":"A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted Document Type Definition (DTD) content. This could lead to an infinite loop during parsing, resulting in a Denial of Service (DoS) for the application using libexpat."},"relatedVulnerabilities":[{"id":"CVE-2026-32777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32777","date":"2026-10-08","epss":0.00174,"percentile":0.06263}],"urls":["https://github.com/libexpat/libexpat/issues/1161","https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1162","https://issues.oss-fuzz.com/issues/486993411","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32777","description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content."}]},{"artifact":{"id":"096f075fd829349b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.5-6.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.5-6.el9_8.src.rpm","type":"rpm","version":"1:3.5.5-6.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.5-6.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.5-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.07772,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75803","description":"A flaw in OpenSSL causes EVP_Cipher() to skip AEAD tag verification for ChaCha20-Poly1305 and AES-OCB ciphers when decrypting empty ciphertexts. This allows remote attackers to submit forged messages that affected applications incorrectly accept as valid."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"a6c320bbdb2151ba","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=libpng-1.6.37-15.el9_8.2.src.rpm","type":"rpm","version":"2:1.6.37-15.el9_8.2","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-64506","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libpng","version":"2:1.6.37-15.el9_8.2"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-64506","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64506","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64506","date":"2026-10-08","epss":0.0014,"percentile":0.02868}],"risk":0.07769999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-64506","description":"A buffer over read flaw has been discovered in libpng. A heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images through the simplified write API with convert_to_8bit enabled. The vulnerability affects 8-bit grayscale+alpha, RGB/RGBA, and images with incomplete row data. A conditional guard incorrectly allows 8-bit input to enter code expecting 16-bit input, causing reads up to 2 bytes beyond allocated buffer boundaries."},"relatedVulnerabilities":[{"id":"CVE-2025-64506","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64506","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64506","date":"2026-10-08","epss":0.0014,"percentile":0.02868}],"urls":["https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821","https://github.com/pnggroup/libpng/pull/749","https://github.com/pnggroup/libpng/security/advisories/GHSA-qpr4-xm66-hww6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-64506","description":"LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images through the simplified write API with convert_to_8bit enabled. The vulnerability affects 8-bit grayscale+alpha, RGB/RGBA, and images with incomplete row data. A conditional guard incorrectly allows 8-bit input to enter code expecting 16-bit input, causing reads up to 2 bytes beyond allocated buffer boundaries. This issue has been patched in version 1.6.51."}]},{"artifact":{"id":"58e822e367013732","cpes":["cpe:2.3:a:redhat:sed:4.8-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:sed:sed:4.8-10.el9:*:*:*:*:*:*:*"],"name":"sed","purl":"pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=rhel-9.8&upstream=sed-4.8-10.el9.src.rpm","type":"rpm","version":"4.8-10.el9","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5958","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"sed","version":"0:4.8-10.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-5958","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5958","cwe":"CWE-367","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-5958","date":"2026-10-08","epss":0.00137,"percentile":0.02701}],"risk":0.07740499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5958","description":"A Time-of-Check Time-of-Use (TOCTOU) race condition was found in GNU sed. When the -i (in-place) and --follow-symlinks options are used together, sed resolves the symlink but reopens the path for writing. An attacker with write access to the directory containing the symlink can swap it between the check and the open operations. If a privileged user executes sed in this manner on a path influenced by the attacker, it can lead to arbitrary file overwrites and potential privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-5958","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5958","cwe":"CWE-367","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-5958","date":"2026-10-08","epss":0.00137,"percentile":0.02701}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-5958","https://www.gnu.org/software/sed/","http://www.openwall.com/lists/oss-security/2026/05/13/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5958","description":"When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores the resolved path for determining when output is written,\n2. opens the original symlink path (not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1. This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0774,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95818","description":"A flaw was found in glibc, the GNU C Library. A local attacker can exploit a stack-based buffer overflow in the dynamic loader (ld.so) when a setuid/setgid (AT_SECURE) program's DT_RPATH or DT_RUNPATH begins with $ORIGIN followed by a null character or a slash. This vulnerability allows the attacker to crash the loader, leading to a denial of service, and potentially disclose limited process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0774,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95818","description":"A flaw was found in glibc, the GNU C Library. A local attacker can exploit a stack-based buffer overflow in the dynamic loader (ld.so) when a setuid/setgid (AT_SECURE) program's DT_RPATH or DT_RUNPATH begins with $ORIGIN followed by a null character or a slash. This vulnerability allows the attacker to crash the loader, leading to a denial of service, and potentially disclose limited process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0774,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95818","description":"A flaw was found in glibc, the GNU C Library. A local attacker can exploit a stack-based buffer overflow in the dynamic loader (ld.so) when a setuid/setgid (AT_SECURE) program's DT_RPATH or DT_RUNPATH begins with $ORIGIN followed by a null character or a slash. This vulnerability allows the attacker to crash the loader, leading to a denial of service, and potentially disclose limited process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56404","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56404","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56404","date":"2026-10-08","epss":0.0013,"percentile":0.02244}],"risk":0.07734999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56404","description":"A flaw was found in libexpat. This vulnerability, an integer overflow in the `addBinding` function, could allow a local attacker to execute arbitrary code. By exploiting this, an attacker could gain control over the affected system, compromising its confidentiality and integrity."},"relatedVulnerabilities":[{"id":"CVE-2026-56404","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56404","date":"2026-10-08","epss":0.0013,"percentile":0.02244}],"urls":["https://github.com/libexpat/libexpat/pull/1249"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56404","description":"libexpat before 2.8.2 has an integer overflow in addBinding."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3479","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"risk":0.077175,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3479","description":"A flaw was found in Python's `pkgutil.get_data()` function, which is used to retrieve data from packages. This function did not properly validate the `resource` argument, allowing a local attacker to perform path traversal attacks. Path traversal enables an attacker to access files and directories stored outside the intended root directory, potentially leading to information disclosure or unintended file access."},"relatedVulnerabilities":[{"id":"CVE-2026-3479","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"severity":"Negligible","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3479","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"risk":0.077175,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3479","description":"A flaw was found in Python's `pkgutil.get_data()` function, which is used to retrieve data from packages. This function did not properly validate the `resource` argument, allowing a local attacker to perform path traversal attacks. Path traversal enables an attacker to access files and directories stored outside the intended root directory, potentially leading to information disclosure or unintended file access."},"relatedVulnerabilities":[{"id":"CVE-2026-3479","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"severity":"Negligible","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."}]},{"artifact":{"id":"a6c320bbdb2151ba","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.37-15.el9_8.2:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=libpng-1.6.37-15.el9_8.2.src.rpm","type":"rpm","version":"2:1.6.37-15.el9_8.2","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-34757","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libpng","version":"2:1.6.37-15.el9_8.2"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-34757","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34757","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34757","date":"2026-10-08","epss":0.00163,"percentile":0.05037}],"risk":0.07661,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-34757","description":"A flaw was found in libpng, a library used for handling PNG (Portable Network Graphics) image files. This vulnerability arises when an application reuses a pointer, previously obtained from functions like png_get_PLTE, by passing it back to a corresponding setter function within the same image structure. This action causes the setter to access memory that has already been deallocated, leading to a use-after-free condition. A local attacker could potentially exploit this flaw to corrupt image metadata or disclose sensitive information from the application's memory."},"relatedVulnerabilities":[{"id":"CVE-2026-34757","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.1,"impactScore":2.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34757","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34757","date":"2026-10-08","epss":0.00163,"percentile":0.05037}],"urls":["https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a","https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc","https://github.com/pnggroup/libpng/issues/836","https://github.com/pnggroup/libpng/issues/837","https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645","https://lists.debian.org/debian-lts-announce/2026/05/msg00017.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34757","description":"LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.0744,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86805","description":"A flaw was found in glibc, specifically within its dynamic loader (ld.so). A local attacker can exploit a time-of-check to time-of-use (TOCTOU) race condition to escalate privileges and execute arbitrary code. This occurs when the dynamic loader expands $ORIGIN in DT_RPATH for setuid/setgid programs, validating a normalized path but then opening an un-normalized path. By hard-linking such a program and winning a race to swap a path component with a symbolic link, an attacker can direct the loader to an attacker-controlled shared object, gaining elevated privileges. This vulnerability is mitigated on systems with fs.protected_hardlinks enabled."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.0744,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86805","description":"A flaw was found in glibc, specifically within its dynamic loader (ld.so). A local attacker can exploit a time-of-check to time-of-use (TOCTOU) race condition to escalate privileges and execute arbitrary code. This occurs when the dynamic loader expands $ORIGIN in DT_RPATH for setuid/setgid programs, validating a normalized path but then opening an un-normalized path. By hard-linking such a program and winning a race to swap a path component with a symbolic link, an attacker can direct the loader to an attacker-controlled shared object, gaining elevated privileges. This vulnerability is mitigated on systems with fs.protected_hardlinks enabled."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.0744,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86805","description":"A flaw was found in glibc, specifically within its dynamic loader (ld.so). A local attacker can exploit a time-of-check to time-of-use (TOCTOU) race condition to escalate privileges and execute arbitrary code. This occurs when the dynamic loader expands $ORIGIN in DT_RPATH for setuid/setgid programs, validating a normalized path but then opening an un-normalized path. By hard-linking such a program and winning a race to swap a path component with a symbolic link, an attacker can direct the loader to an attacker-controlled shared object, gaining elevated privileges. This vulnerability is mitigated on systems with fs.protected_hardlinks enabled."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"2e7650523e20cfd7","cpes":["cpe:2.3:a:freetype:freetype:2.10.4-10.el9_5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:freetype:2.10.4-10.el9_5:*:*:*:*:*:*:*"],"name":"freetype","purl":"pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=rhel-9.8&upstream=freetype-2.10.4-10.el9_5.src.rpm","type":"rpm","version":"2.10.4-10.el9_5","language":"","licenses":["(FTL or GPLv2+) and BSD and MIT and Public Domain and zlib with acknowledgement"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-23865","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"freetype","version":"0:2.10.4-10.el9_5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-23865","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23865","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-23865","date":"2026-10-08","epss":0.00144,"percentile":0.03165}],"risk":0.07416,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-23865","description":"A flaw was found in Freetype. An integer overflow vulnerability exists when processing specially crafted OpenType variable fonts. A local attacker could exploit this by convincing a user to open a malicious font file, which may lead to an out-of-bounds read and potential information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-23865","cvss":[{"type":"Secondary","source":"cve-assign@fb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23865","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-23865","date":"2026-10-08","epss":0.00144,"percentile":0.03165}],"urls":["https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c","https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/","https://www.facebook.com/security/advisories/cve-2026-23865","http://www.openwall.com/lists/oss-security/2026/03/03/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23865","description":"An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86469","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86469","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"risk":0.07261500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86469","description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file."},"relatedVulnerabilities":[{"id":"CVE-2026-86469","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"urls":["https://access.redhat.com/security/cve/CVE-2026-86469","https://bugzilla.redhat.com/show_bug.cgi?id=2473839","https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c","https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86469","description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18374","description":"A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the `fopen` function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18374","description":"A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the `fopen` function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18374","description":"A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the `fopen` function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.06615000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0864","description":"A flaw was found in the Python `configparser` module. When writing configuration files, an attacker who controls the input value can inject unexpected keys and values. This occurs if the input contains multi-line text with carriage return characters, leading to potential configuration manipulation."},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.06615000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0864","description":"A flaw was found in the Python `configparser` module. When writing configuration files, an attacker who controls the input value can inject unexpected keys and values. This occurs if the input contains multi-line text with carriage return characters, leading to potential configuration manipulation."},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"2034e22d42620422","cpes":["cpe:2.3:a:jline-reader:jline-reader:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline-reader:jline_reader:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_reader:jline-reader:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline_reader:jline_reader:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-reader:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_reader:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-reader:3.30.4:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_reader:3.30.4:*:*:*:*:*:*:*"],"name":"jline-reader","purl":"pkg:maven/org.jline/jline-reader@3.30.4","type":"java-archive","version":"3.30.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/java/kafka/jline-3.30.4.jar:org.jline:jline-reader","manifestName":"","pomArtifactID":"jline-reader","archiveDigests":null},"locations":[{"path":"/usr/share/java/kafka/jline-3.30.4.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/jline-3.30.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5q95-hrpc-m3w3","versionConstraint":">=3.0.0,<3.30.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-reader","version":"3.30.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5q95-hrpc-m3w3","fix":{"state":"fixed","versions":["3.30.15"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"3.30.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77420","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77420","date":"2026-10-08","epss":0.00123,"percentile":0.0183}],"risk":0.06457500000000001,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5q95-hrpc-m3w3","description":"JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable"},"relatedVulnerabilities":[{"id":"CVE-2026-77420","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77420","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77420","date":"2026-10-08","epss":0.00123,"percentile":0.0183}],"urls":["https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15","https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77420","description":"JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration value into a Java regular expression while escaping only part of its syntax, allowing other regex metacharacters to reach the backtracking engine. An attacker who can control application or user configuration can supply a nested-quantifier expression that is reevaluated whenever a command is added to history, consuming excessive CPU and indefinitely blocking the reader thread. This issue is fixed in versions 3.30.15 and 4.3.1."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-2297","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-2297","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2297","cwe":"CWE-668","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-2297","date":"2026-10-08","epss":0.00201,"percentile":0.09175}],"risk":0.063315,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-2297","description":"A flaw was found in CPython. This vulnerability allows a local user with low privileges to bypass security auditing mechanisms. The issue occurs because the SourcelessFileLoader component, responsible for handling older Python compiled files (.pyc), does not properly trigger system audit events. This oversight could enable malicious activities to go undetected, compromising the integrity of the system."},"relatedVulnerabilities":[{"id":"CVE-2026-2297","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2297","cwe":"CWE-668","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-2297","date":"2026-10-08","epss":0.00201,"percentile":0.09175}],"urls":["https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e","https://github.com/python/cpython/commit/69ddd9bb2cc4bd69b1565647c18659c6a789ccd9","https://github.com/python/cpython/commit/876858c9f65d9ab656c7fa639f268ce7856d89dd","https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e","https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66","https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86","https://github.com/python/cpython/issues/145506","https://github.com/python/cpython/pull/145507","http://www.openwall.com/lists/oss-security/2026/03/05/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2297","description":"The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-2297","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-2297","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2297","cwe":"CWE-668","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-2297","date":"2026-10-08","epss":0.00201,"percentile":0.09175}],"risk":0.063315,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-2297","description":"A flaw was found in CPython. This vulnerability allows a local user with low privileges to bypass security auditing mechanisms. The issue occurs because the SourcelessFileLoader component, responsible for handling older Python compiled files (.pyc), does not properly trigger system audit events. This oversight could enable malicious activities to go undetected, compromising the integrity of the system."},"relatedVulnerabilities":[{"id":"CVE-2026-2297","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2297","cwe":"CWE-668","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-2297","date":"2026-10-08","epss":0.00201,"percentile":0.09175}],"urls":["https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e","https://github.com/python/cpython/commit/69ddd9bb2cc4bd69b1565647c18659c6a789ccd9","https://github.com/python/cpython/commit/876858c9f65d9ab656c7fa639f268ce7856d89dd","https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e","https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66","https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86","https://github.com/python/cpython/issues/145506","https://github.com/python/cpython/pull/145507","http://www.openwall.com/lists/oss-security/2026/03/05/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2297","description":"The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56405","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56405","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56405","date":"2026-10-08","epss":0.00125,"percentile":0.0192}],"risk":0.061875000000000006,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56405","description":"A flaw was found in libexpat. An integer overflow vulnerability exists within the `getAttributeId` function. This flaw could allow an attacker to potentially disclose sensitive information or execute arbitrary code, leading to a compromise of the system's integrity and confidentiality."},"relatedVulnerabilities":[{"id":"CVE-2026-56405","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56405","date":"2026-10-08","epss":0.00125,"percentile":0.0192}],"urls":["https://github.com/libexpat/libexpat/pull/1251"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56405","description":"libexpat before 2.8.2 has an integer overflow in getAttributeId."}]},{"artifact":{"id":"9d4b5e84721dd1cf","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/lz4-java-1.11.1.jar","layerID":"sha256:f67820dc57daf56286bb2eddc3518fa16be67f27c7aa2c53f39dbf8b3c4f72ac","accessPath":"/usr/share/java/kafka/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mcr4-qmvw-px4g","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mcr4-qmvw-px4g","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"risk":0.061419999999999995,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g","https://nvd.nist.gov/vuln/detail/CVE-2026-106451","https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mcr4-qmvw-px4g","description":"yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user"},"relatedVulnerabilities":[{"id":"CVE-2026-106451","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"urls":["https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","description":"yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"448588eb4147df6f","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["\"Apache License, Version 2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0\""],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"140124bf632168cef73cf9ce80477dced52b2443","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","layerID":"sha256:9f18dfc61baff332293d61da717da84fef85aa91f6b3798a9798d46d577a66e9","accessPath":"/usr/share/java/cp-base-java-micro/lz4-java-1.11.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mcr4-qmvw-px4g","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mcr4-qmvw-px4g","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"risk":0.061419999999999995,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g","https://nvd.nist.gov/vuln/detail/CVE-2026-106451","https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mcr4-qmvw-px4g","description":"yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user"},"relatedVulnerabilities":[{"id":"CVE-2026-106451","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"urls":["https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","description":"yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"3b95a370d9cbeb72","cpes":["cpe:2.3:a:redhat:zlib:1.2.11-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:zlib:zlib:1.2.11-40.el9:*:*:*:*:*:*:*"],"name":"zlib","purl":"pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=rhel-9.8&upstream=zlib-1.2.11-40.el9.src.rpm","type":"rpm","version":"1.2.11-40.el9","language":"","licenses":["zlib and Boost"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"zlib","version":"0:1.2.11-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"risk":0.06016499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27171","description":"A flaw was found in zlib. An attacker providing specially crafted input to the `crc32_combine64` or `crc32_combine_gen64` functions could trigger an infinite loop within the `x2nmodp` function. This leads to excessive CPU consumption, which can result in a Denial of Service (DoS) for the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.05988500000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-66382","description":"A flaw was found in libexpat. This vulnerability allows a denial of service (DoS) by processing a crafted file with an approximate size of 2 MiB, leading to dozens of seconds of processing time."},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"9356f22b5dfd0bcd","cpes":["cpe:2.3:a:alsa-lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=rhel-9.8&upstream=alsa-lib-1.2.15.3-1.el9.src.rpm","type":"rpm","version":"1.2.15.3-1.el9","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-96675","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"alsa-lib","version":"0:1.2.15.3-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-96675","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96675","cwe":"CWE-129","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-96675","date":"2026-10-08","epss":0.00111,"percentile":0.01223}],"risk":0.05827500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-96675","description":"A flaw was found in alsa-lib. This denial of service vulnerability exists in the multi PCM plugin due to a failure to validate sparse binding indices before array access. A local attacker can supply a malicious ALSA configuration file with sparse bindings. This can trigger an out-of-bounds array read and assertion failure, causing the application to terminate unexpectedly."},"relatedVulnerabilities":[{"id":"CVE-2026-96675","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96675","cwe":"CWE-129","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-96675","date":"2026-10-08","epss":0.00111,"percentile":0.01223}],"urls":["https://github.com/alsa-project/alsa-lib","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/pcm/pcm_multi.c#L1122-L1131","https://github.com/alsa-project/alsa-lib/pull/527","https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-denial-of-service-via-pcm-multi"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-96675","description":"alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort."}]},{"artifact":{"id":"aff0baca8a045287","cpes":["cpe:2.3:a:libblkid:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libblkid","purl":"pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"66ba386a85828620","cpes":["cpe:2.3:a:libmount:libmount:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libmount:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libmount","purl":"pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"63e8f89642ab1486","cpes":["cpe:2.3:a:libuuid:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libuuid","purl":"pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"38f70d6bae6b19d1","cpes":["cpe:2.3:a:libgcrypt:libgcrypt:1.10.0-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcrypt:1.10.0-13.el9_8:*:*:*:*:*:*:*"],"name":"libgcrypt","purl":"pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libgcrypt-1.10.0-13.el9_8.src.rpm","type":"rpm","version":"1.10.0-13.el9_8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41990","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libgcrypt","version":"0:1.10.0-13.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-41990","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.3,"impactScore":2.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41990","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41990","date":"2026-10-08","epss":0.0018,"percentile":0.06954}],"risk":0.05669999999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-41990","description":"A flaw was found in Libgcrypt. During Dilithium signing operations, the library fails to perform a bounds check when writing to a static array. While the data involved is not directly controlled by an attacker, this vulnerability could lead to memory corruption, potentially resulting in a denial of service (DoS) or affecting data integrity."},"relatedVulnerabilities":[{"id":"CVE-2026-41990","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4,"impactScore":2.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41990","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41990","date":"2026-10-08","epss":0.0018,"percentile":0.06954}],"urls":["https://dev.gnupg.org/T8208","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html","https://www.openwall.com/lists/oss-security/2026/04/21/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41990","description":"Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data."}]},{"artifact":{"id":"3d387c5ca38febed","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.056174999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6368","description":"A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.056174999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6368","description":"A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.056174999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6368","description":"A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"bb1caebf00bfd67f","cpes":["cpe:2.3:a:libX11:libX11:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11","purl":"pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-94285","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"0:1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-94285","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.1,"impactScore":2.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94285","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94285","date":"2026-10-08","epss":0.00111,"percentile":0.01263}],"risk":0.05605500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-94285","description":"A flaw was found in libX11. An out-of-bounds read vulnerability in the byte-oriented codeset parser allows a malicious X Window System server to cause a Denial of Service (DoS) by crashing connected client applications. This issue may also allow the server to access limited memory contents from the client."},"relatedVulnerabilities":[{"id":"CVE-2026-94285","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.1,"impactScore":2.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94285","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94285","date":"2026-10-08","epss":0.00111,"percentile":0.01263}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94285","description":"An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"6a1cd4ae8b36edce","cpes":["cpe:2.3:a:libX11-common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11-common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11-common","purl":"pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libX11","version":"1.8.12-1.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94285","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-94285","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.1,"impactScore":2.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94285","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94285","date":"2026-10-08","epss":0.00111,"percentile":0.01263}],"risk":0.05605500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-94285","description":"A flaw was found in libX11. An out-of-bounds read vulnerability in the byte-oriented codeset parser allows a malicious X Window System server to cause a Denial of Service (DoS) by crashing connected client applications. This issue may also allow the server to access limited memory contents from the client."},"relatedVulnerabilities":[{"id":"CVE-2026-94285","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.1,"impactScore":2.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94285","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94285","date":"2026-10-08","epss":0.00111,"percentile":0.01263}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94285","description":"An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-24515","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-24515","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-24515","date":"2026-10-08","epss":0.00189,"percentile":0.07816}],"risk":0.055755,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-24515","description":"A null pointer dereference flaw has been discovered in libexpat. The function `XML_ExternalEntityParserCreate` failed to copy the encoding handler data passed to XML_SetUnknownEncodingHandler from the parent to the new subparser. This can cause a NULL dereference from external entities that declare use of an unknown encoding. The expected impact is denial of service. It takes use of both functions `XML_ExternalEntityParserCreate` and `XML_SetUnknownEncodingHandler` for an application to be vulnerable."},"relatedVulnerabilities":[{"id":"CVE-2026-24515","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-24515","date":"2026-10-08","epss":0.00189,"percentile":0.07816}],"urls":["https://github.com/libexpat/libexpat/pull/1131","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24515","description":"In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data."}]},{"artifact":{"id":"bb1caebf00bfd67f","cpes":["cpe:2.3:a:libX11:libX11:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11","purl":"pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-94284","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"0:1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-94284","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94284","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94284","date":"2026-10-08","epss":0.00103,"percentile":0.00924}],"risk":0.05407500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-94284","description":"A flaw was found in libX11. An out-of-bounds read vulnerability exists in the X Input Method (XIM) trigger-key registration parser. A malicious X server can exploit this flaw by sending specially crafted trigger-key registration data to connected client applications, causing them to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-94284","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94284","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94284","date":"2026-10-08","epss":0.00103,"percentile":0.00924}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94284","description":"An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"6a1cd4ae8b36edce","cpes":["cpe:2.3:a:libX11-common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11-common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11-common","purl":"pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libX11","version":"1.8.12-1.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94284","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-94284","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94284","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94284","date":"2026-10-08","epss":0.00103,"percentile":0.00924}],"risk":0.05407500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-94284","description":"A flaw was found in libX11. An out-of-bounds read vulnerability exists in the X Input Method (XIM) trigger-key registration parser. A malicious X server can exploit this flaw by sending specially crafted trigger-key registration data to connected client applications, causing them to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-94284","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94284","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94284","date":"2026-10-08","epss":0.00103,"percentile":0.00924}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94284","description":"An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"9356f22b5dfd0bcd","cpes":["cpe:2.3:a:alsa-lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.15.3-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.15.3-1.el9:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=rhel-9.8&upstream=alsa-lib-1.2.15.3-1.el9.src.rpm","type":"rpm","version":"1.2.15.3-1.el9","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-96674","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"alsa-lib","version":"0:1.2.15.3-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-96674","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96674","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-96674","date":"2026-10-08","epss":0.00115,"percentile":0.01438}],"risk":0.05405000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-96674","description":"A flaw was found in alsa-lib. This vulnerability involves an integer overflow in the src/topology/ctl.c component, where combined topology element sizes are computed using 32-bit arithmetic. This allows an attacker to supply specially crafted topology files that can cause size calculations to wrap around, bypassing bounds checks. Successful exploitation could lead to reading beyond the intended buffer, potentially resulting in sensitive data leakage or application crashes, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-96674","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96674","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-96674","date":"2026-10-08","epss":0.00115,"percentile":0.01438}],"urls":["https://github.com/alsa-project/alsa-lib","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521","https://github.com/alsa-project/alsa-lib/pull/527","https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-integer-overflow-via-topology-file"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-96674","description":"alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application."}]},{"artifact":{"id":"2e7650523e20cfd7","cpes":["cpe:2.3:a:freetype:freetype:2.10.4-10.el9_5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:freetype:2.10.4-10.el9_5:*:*:*:*:*:*:*"],"name":"freetype","purl":"pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=rhel-9.8&upstream=freetype-2.10.4-10.el9_5.src.rpm","type":"rpm","version":"2.10.4-10.el9_5","language":"","licenses":["(FTL or GPLv2+) and BSD and MIT and Public Domain and zlib with acknowledgement"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-49919","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"freetype","version":"0:2.10.4-10.el9_5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-49919","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49919","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-49919","date":"2026-10-08","epss":0.00099,"percentile":0.0078}],"risk":0.05346,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-49919","description":"A flaw was found in FreeType. An attacker could cause an application crash leading to a Denial of Service (DoS) by tricking a user or application into rendering a specially crafted color font. This issue occurs due to an integer overflow during bitmap dimension calculations when blending color font layers, resulting in an undersized memory allocation. FreeType subsequently performs an out-of-bounds write to heap memory, corrupting process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-49919","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49919","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-49919","date":"2026-10-08","epss":0.00099,"percentile":0.0078}],"urls":["https://source.android.com/docs/security/bulletin/2026/2026-09-01"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49919","description":"In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."}]},{"artifact":{"id":"9be73946849192cb","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.3:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.3.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76957","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-76957","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76957","date":"2026-10-08","epss":0.00107,"percentile":0.01051}],"risk":0.052965,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-76957","description":"A flaw was found in libexpat. The library's handling of custom encoding callbacks lacks proper tracking of handler call depth, which can lead to a use-after-free vulnerability. This memory corruption flaw could allow a local attacker to cause a denial of service or potentially execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2026-76957","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76957","date":"2026-10-08","epss":0.00107,"percentile":0.01051}],"urls":["https://github.com/libexpat/libexpat/pull/1322","https://github.com/libexpat/libexpat/pull/1329"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76957","description":"libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1485","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1485","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1485","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1485","date":"2026-10-08","epss":0.00158,"percentile":0.04386}],"risk":0.04582,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1485","description":"A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-1485","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1485","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1485","date":"2026-10-08","epss":0.00158,"percentile":0.04386}],"urls":["https://access.redhat.com/security/cve/CVE-2026-1485","https://bugzilla.redhat.com/show_bug.cgi?id=2433325","https://gitlab.gnome.org/GNOME/glib/-/issues/3871"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1485","description":"A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-13462","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-13462","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13462","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-13462","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-13462","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13462","date":"2026-10-08","epss":0.00164,"percentile":0.05122}],"risk":0.0451,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-13462","description":"A flaw was found in the `tarfile` module of cpython. This vulnerability allows a remote attacker to craft a malicious tar archive that, when processed, could be misinterpreted by the `tarfile` module. This misinterpretation occurs because the module incorrectly applies normalization of `AREGTYPE` blocks to `DIRTYPE` during the processing of multi-block members, such as `GNUTYPE_LONGNAME` or `GNUTYPE_LONGLINK`. The consequence is that the `tarfile` module may process the archive differently than intended, potentially leading to unexpected file system changes or data integrity issues."},"relatedVulnerabilities":[{"id":"CVE-2025-13462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13462","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-13462","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-13462","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13462","date":"2026-10-08","epss":0.00164,"percentile":0.05122}],"urls":["https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab","https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114","https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017","https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406","https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7","https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084","https://github.com/python/cpython/issues/141707","https://github.com/python/cpython/pull/143934","https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13462","description":"The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-13462","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-13462","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13462","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-13462","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-13462","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13462","date":"2026-10-08","epss":0.00164,"percentile":0.05122}],"risk":0.0451,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-13462","description":"A flaw was found in the `tarfile` module of cpython. This vulnerability allows a remote attacker to craft a malicious tar archive that, when processed, could be misinterpreted by the `tarfile` module. This misinterpretation occurs because the module incorrectly applies normalization of `AREGTYPE` blocks to `DIRTYPE` during the processing of multi-block members, such as `GNUTYPE_LONGNAME` or `GNUTYPE_LONGLINK`. The consequence is that the `tarfile` module may process the archive differently than intended, potentially leading to unexpected file system changes or data integrity issues."},"relatedVulnerabilities":[{"id":"CVE-2025-13462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13462","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-13462","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-13462","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13462","date":"2026-10-08","epss":0.00164,"percentile":0.05122}],"urls":["https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab","https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114","https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017","https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406","https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7","https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084","https://github.com/python/cpython/issues/141707","https://github.com/python/cpython/pull/143934","https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13462","description":"The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations."}]},{"artifact":{"id":"ea0f2a7e0eb5d962","cpes":["cpe:2.3:a:python3:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.03451,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18503","description":"A flaw was found in the `csv.Sniffer.sniff()` function within Python. An attacker can exploit this by providing specially crafted CSV samples, which can trigger super-linear regular-expression processing during dialect sniffing. This excessive processing consumes significant CPU resources, potentially leading to a Denial of Service (DoS) for applications that process unbounded input using this function."},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"0ed3c72bb9ee9391","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.9.25-7.el9_8.3:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=rhel-9.8&upstream=python3.9-3.9.25-7.el9_8.3.src.rpm","type":"rpm","version":"3.9.25-7.el9_8.3","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3.9","version":"3.9.25-7.el9_8.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"python3.9","version":"3.9.25-7.el9_8.3"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.03451,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18503","description":"A flaw was found in the `csv.Sniffer.sniff()` function within Python. An attacker can exploit this by providing specially crafted CSV samples, which can trigger super-linear regular-expression processing during dialect sniffing. This excessive processing consumes significant CPU resources, potentially leading to a Denial of Service (DoS) for applications that process unbounded input using this function."},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"ac92e4b914d0f365","cpes":["cpe:2.3:a:gnutls:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=rhel-9.8&upstream=gnutls-3.8.10-8.el9_8.src.rpm","type":"rpm","version":"3.8.10-8.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-88647","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-8.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-88647","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-88647","description":"A flaw was found in GnuTLS. This vulnerability can lead to information disclosure by allowing an attacker to bypass certificate hostname verification. A remote attacker presenting a crafted certificate can circumvent the Common Name fallback check, enabling them to eavesdrop on or intercept encrypted network communications."},"relatedVulnerabilities":[{"id":"CVE-2026-88647","cvss":[],"urls":["https://gist.github.com/lkloliver/f98ec3de1a871fdfc02b70b8b9ba7642","https://gitlab.com/gnutls/gnutls/-/issues/1802"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88647","description":"A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate."}]},{"artifact":{"id":"ac92e4b914d0f365","cpes":["cpe:2.3:a:gnutls:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=rhel-9.8&upstream=gnutls-3.8.10-8.el9_8.src.rpm","type":"rpm","version":"3.8.10-8.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-88648","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-8.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-88648","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-88648","description":"A flaw was found in GnuTLS. An attacker controlling a subordinate Certificate Authority (CA) can exploit an incomplete X.509 certificate validation mechanism to bypass cross-domain Public Key Infrastructure (PKI) restrictions. This allows unauthorized certificates to be accepted as valid, potentially enabling the attacker to impersonate trusted domains and intercept secure communications."},"relatedVulnerabilities":[{"id":"CVE-2026-88648","cvss":[],"urls":["https://gist.github.com/lkloliver/1f2a97cb8d0b31aa27b6bd0354358d7d","https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10","https://www.rfc-editor.org/rfc/rfc5280#section-6.1.4"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88648","description":"Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates."}]},{"artifact":{"id":"aff0baca8a045287","cpes":["cpe:2.3:a:libblkid:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libblkid","purl":"pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"66ba386a85828620","cpes":["cpe:2.3:a:libmount:libmount:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libmount:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libmount","purl":"pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"63e8f89642ab1486","cpes":["cpe:2.3:a:libuuid:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libuuid","purl":"pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"ac92e4b914d0f365","cpes":["cpe:2.3:a:gnutls:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=rhel-9.8&upstream=gnutls-3.8.10-8.el9_8.src.rpm","type":"rpm","version":"3.8.10-8.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-67693","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-8.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-67693","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-67693","description":"A flaw was found in GnuTLS. The certificate verification process fails to properly reject end-entity digital certificates containing contradictory Key Usage (KU) and Extended Key Usage (EKU) extensions, which define the permitted cryptographic operations of a certificate. A remote attacker could exploit this flaw by presenting a specially crafted certificate to bypass validation controls, potentially resulting in information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-67693","cvss":[],"urls":["http://gnutls.com","https://gist.github.com/lkloliver/6fbfc191bc6163942c8017551ac3f238","https://gitlab.com/gnutls/gnutls/-/blob/3.8.13/lib/x509/verify.c#L1119-1178"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67693","description":"An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)"}]},{"artifact":{"id":"bb1caebf00bfd67f","cpes":["cpe:2.3:a:libX11:libX11:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11","purl":"pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-3554","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"0:1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-3554","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-3554","description":"A flaw was found in LibX11. There is a possible memory leak in the _XimRegisterIMInstantiateCallback() of modules/im/ximcp/imsClbk.c. This issue may lead to limited availability."},"relatedVulnerabilities":[{"id":"CVE-2022-3554","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3554","description":"Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}]},{"artifact":{"id":"6a1cd4ae8b36edce","cpes":["cpe:2.3:a:libX11-common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11-common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11-common","purl":"pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libX11","version":"1.8.12-1.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3554","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-3554","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-3554","description":"A flaw was found in LibX11. There is a possible memory leak in the _XimRegisterIMInstantiateCallback() of modules/im/ximcp/imsClbk.c. This issue may lead to limited availability."},"relatedVulnerabilities":[{"id":"CVE-2022-3554","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3554","description":"Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}]},{"artifact":{"id":"bb1caebf00bfd67f","cpes":["cpe:2.3:a:libX11:libX11:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11","purl":"pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-3555","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"0:1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-3555","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-3555","description":"A flaw was found in the libX11 package in the_XFreeX11XCBStructure function of the xcb_disp.c file. The manipulation of the argument dpy may lead to a memory leak, resulting in a crash."},"relatedVulnerabilities":[{"id":"CVE-2022-3555","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3555","description":"Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}]},{"artifact":{"id":"6a1cd4ae8b36edce","cpes":["cpe:2.3:a:libX11-common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11-common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11_common:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:libX11:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11-common:1.8.12-1.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libX11_common:1.8.12-1.el9:*:*:*:*:*:*:*"],"name":"libX11-common","purl":"pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=rhel-9.8&upstream=libX11-1.8.12-1.el9.src.rpm","type":"rpm","version":"1.8.12-1.el9","language":"","licenses":["MIT AND X11"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libX11","version":"1.8.12-1.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3555","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libX11","version":"1.8.12-1.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-3555","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-3555","description":"A flaw was found in the libX11 package in the_XFreeX11XCBStructure function of the xcb_disp.c file. The manipulation of the argument dpy may lead to a memory leak, resulting in a crash."},"relatedVulnerabilities":[{"id":"CVE-2022-3555","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3555","description":"Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}]},{"artifact":{"id":"2e7650523e20cfd7","cpes":["cpe:2.3:a:freetype:freetype:2.10.4-10.el9_5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:freetype:2.10.4-10.el9_5:*:*:*:*:*:*:*"],"name":"freetype","purl":"pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=rhel-9.8&upstream=freetype-2.10.4-10.el9_5.src.rpm","type":"rpm","version":"2.10.4-10.el9_5","language":"","licenses":["(FTL or GPLv2+) and BSD and MIT and Public Domain and zlib with acknowledgement"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:d94576616f0d4aafd6fd57298e1e9db141fcd75eac7a25f055c8525a349da825","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-2004","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"freetype","version":"0:2.10.4-10.el9_5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-2004","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","metrics":{"baseScore":0,"impactScore":0,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"Negligible","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-2004","description":"An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c. This flaw causes an application to crash or leads to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2023-2004","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2004","description":"Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"d824797f9a216cbb","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/package_dedupe","layerID":"sha256:faa4b8b515c939b709919184b871f13c12319712d781cc75f03013cefe8e8dd6","accessPath":"/usr/bin/package_dedupe","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]},{"artifact":{"id":"9df7c13df16482d8","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/ub","layerID":"sha256:f5197b933561d5ac26b7ddfc5079729c39a1e5c9bc3e006b177cbcf790a5e25c","accessPath":"/usr/bin/ub","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:32:01.226Z","grype_db_version":"2026-10-09T06:32:32.000Z"}