{"grype_matches":[{"artifact":{"id":"e14229d618c86e09","cpes":["cpe:2.3:a:kubectl:kubectl:1.36.1-r0:*:*:*:*:*:*:*"],"name":"kubectl","purl":"pkg:apk/alpine/kubectl@1.36.1-r0?arch=x86_64&distro=alpine-3.24.1&upstream=kubernetes","type":"apk","version":"1.36.1-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/kubectl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"kubernetes"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2020-8554","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:1.36.1:*:*:*:*:*:*:*"],"package":{"name":"kubernetes","version":"1.36.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2020-8554","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"jordan@liggitt.net","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8554","cwe":"CWE-283","type":"Secondary","source":"jordan@liggitt.net"}],"epss":[{"cve":"CVE-2020-8554","date":"2026-10-08","epss":0.09274,"percentile":0.95248}],"risk":4.9925033333333335,"urls":["https://github.com/kubernetes/kubernetes/issues/97076","https://groups.google.com/g/kubernetes-security-announce/c/iZWsF9nbKE8","https://kubernetes.io/blog/2026/05/26/reconciling-unfixed-kubernetes-cves/","https://lists.apache.org/thread.html/r0c76b3d0be348f788cd947054141de0229af00c540564711e828fd40%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r1975078e44d96f2a199aa90aa874b57a202eaf7f25f2fde6d1c44942%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rcafa485d63550657f068775801aeb706b7a07140a8ebbdef822b3bb3%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rdb223e1b82e3d7d8e4eaddce8dd1ab87252e3935cc41c859f49767b6%40%3Ccommits.druid.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8554","description":"Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect."},"relatedVulnerabilities":[]},{"artifact":{"id":"e14229d618c86e09","cpes":["cpe:2.3:a:kubectl:kubectl:1.36.1-r0:*:*:*:*:*:*:*"],"name":"kubectl","purl":"pkg:apk/alpine/kubectl@1.36.1-r0?arch=x86_64&distro=alpine-3.24.1&upstream=kubernetes","type":"apk","version":"1.36.1-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/kubectl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"kubernetes"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-1906","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:1.36.1:*:*:*:*:*:*:*"],"package":{"name":"kubernetes","version":"1.36.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-1906","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1906","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1906","date":"2026-10-08","epss":0.04843,"percentile":0.91783}],"risk":4.5766350000000005,"urls":["https://access.redhat.com/errata/RHSA-2016:0070","https://access.redhat.com/errata/RHSA-2016:0351","https://github.com/openshift/origin/issues/6556","https://github.com/openshift/origin/pull/6576"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1906","description":"Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed."},"relatedVulnerabilities":[]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63076"},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63076"},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63076"},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"e14229d618c86e09","cpes":["cpe:2.3:a:kubectl:kubectl:1.36.1-r0:*:*:*:*:*:*:*"],"name":"kubectl","purl":"pkg:apk/alpine/kubectl@1.36.1-r0?arch=x86_64&distro=alpine-3.24.1&upstream=kubernetes","type":"apk","version":"1.36.1-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/kubectl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"kubernetes"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7075","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:1.36.1:*:*:*:*:*:*:*"],"package":{"name":"kubernetes","version":"1.36.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7075","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7075","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2016-7075","cwe":"CWE-295","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7075","date":"2026-10-08","epss":0.01568,"percentile":0.74591}],"risk":1.1733866666666666,"urls":["https://access.redhat.com/errata/RHSA-2016:2064","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7075","https://github.com/kubernetes/kubernetes/issues/34517"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7075","description":"It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate."},"relatedVulnerabilities":[]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"risk":1.15275,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-18798"},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"risk":1.15275,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-18798"},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"risk":1.15275,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-18798"},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"risk":1.08946,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63073"},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"risk":1.08946,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63073"},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"risk":1.08946,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63073"},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e14229d618c86e09","cpes":["cpe:2.3:a:kubectl:kubectl:1.36.1-r0:*:*:*:*:*:*:*"],"name":"kubectl","purl":"pkg:apk/alpine/kubectl@1.36.1-r0?arch=x86_64&distro=alpine-3.24.1&upstream=kubernetes","type":"apk","version":"1.36.1-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/kubectl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"kubernetes"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-1905","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:1.36.1:*:*:*:*:*:*:*"],"package":{"name":"kubernetes","version":"1.36.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-1905","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.7,"impactScore":4,"exploitabilityScore":3.2},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:P/A:N","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1905","cwe":"CWE-284","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1905","date":"2026-10-08","epss":0.01583,"percentile":0.74801}],"risk":1.0566525,"urls":["https://access.redhat.com/errata/RHSA-2016:0070","https://github.com/kubernetes/kubernetes/issues/19479"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1905","description":"The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object."},"relatedVulnerabilities":[]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"risk":0.76575,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14457"},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"risk":0.76575,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14457"},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"risk":0.76575,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14457"},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63072"},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63072"},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63072"},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"e14229d618c86e09","cpes":["cpe:2.3:a:kubectl:kubectl:1.36.1-r0:*:*:*:*:*:*:*"],"name":"kubectl","purl":"pkg:apk/alpine/kubectl@1.36.1-r0?arch=x86_64&distro=alpine-3.24.1&upstream=kubernetes","type":"apk","version":"1.36.1-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/kubectl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"kubernetes"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2021-25740","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:1.36.1:*:*:*:*:*:*:*"],"package":{"name":"kubernetes","version":"1.36.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2021-25740","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","metrics":{"baseScore":3.5,"impactScore":2.9,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"jordan@liggitt.net","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-25740","cwe":"CWE-441","type":"Secondary","source":"jordan@liggitt.net"},{"cve":"CVE-2021-25740","cwe":"CWE-610","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-25740","date":"2026-10-08","epss":0.01952,"percentile":0.79636}],"risk":0.6083733333333332,"urls":["https://github.com/kubernetes/kubernetes/issues/103675","https://groups.google.com/g/kubernetes-security-announce/c/WYE9ptrhSLE","https://kubernetes.io/blog/2026/05/26/reconciling-unfixed-kubernetes-cves/","https://security.netapp.com/advisory/ntap-20211014-0001/"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-25740","description":"A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack."},"relatedVulnerabilities":[]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.53.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<0.53.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["0.53.0"],"available":[{"date":"2026-04-09","kind":"release","version":"0.53.0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"risk":0.5835,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63075"},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"risk":0.5835,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63075"},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"risk":0.5835,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63075"},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14456"},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14456"},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-14456"},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-39979","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-39979","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-39979","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39979","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-39979","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39979","date":"2026-10-08","epss":0.00824,"percentile":0.56057}],"risk":0.4738,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-39979"},"relatedVulnerabilities":[{"id":"CVE-2026-39979","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39979","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-39979","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39979","date":"2026-10-08","epss":0.00824,"percentile":0.56057}],"urls":["https://github.com/jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f","https://github.com/jqlang/jq/security/advisories/GHSA-2hhh-px8h-355p","https://access.redhat.com/errata/RHSA-2026:16252","https://access.redhat.com/errata/RHSA-2026:16692","https://access.redhat.com/errata/RHSA-2026:16693","https://access.redhat.com/errata/RHSA-2026:18040","https://access.redhat.com/errata/RHSA-2026:18042","https://access.redhat.com/errata/RHSA-2026:18043","https://access.redhat.com/errata/RHSA-2026:18044","https://access.redhat.com/errata/RHSA-2026:18045","https://access.redhat.com/errata/RHSA-2026:18046","https://access.redhat.com/errata/RHSA-2026:18047","https://access.redhat.com/errata/RHSA-2026:18048","https://access.redhat.com/errata/RHSA-2026:19151","https://access.redhat.com/errata/RHSA-2026:19365","https://access.redhat.com/errata/RHSA-2026:23233","https://access.redhat.com/errata/RHSA-2026:23245","https://access.redhat.com/errata/RHSA-2026:25044","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:25181","https://access.redhat.com/errata/RHSA-2026:26528","https://access.redhat.com/errata/RHSA-2026:26542","https://access.redhat.com/errata/RHSA-2026:28887","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:34098","https://access.redhat.com/errata/RHSA-2026:8579","https://access.redhat.com/security/cve/CVE-2026-39979","https://bugzilla.redhat.com/show_bug.cgi?id=2458077","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39979.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39979","description":"jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5942","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5942","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-06-09","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"risk":0.47250000000000003,"urls":["https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/786345","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-46600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"urls":["https://go.dev/cl/786345","https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5942"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46600","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5942","versionConstraint":">=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5942","fix":{"state":"fixed","versions":["1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"risk":0.47250000000000003,"urls":["https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/786345","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-46600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"urls":["https://go.dev/cl/786345","https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5942"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46600","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5942","versionConstraint":">=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5942","fix":{"state":"fixed","versions":["1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"risk":0.47250000000000003,"urls":["https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/786345","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-46600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"urls":["https://go.dev/cl/786345","https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5942"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46600","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-54874"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-54874"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-54874"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"e14229d618c86e09","cpes":["cpe:2.3:a:kubectl:kubectl:1.36.1-r0:*:*:*:*:*:*:*"],"name":"kubectl","purl":"pkg:apk/alpine/kubectl@1.36.1-r0?arch=x86_64&distro=alpine-3.24.1&upstream=kubernetes","type":"apk","version":"1.36.1-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/kubectl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"kubernetes"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2015-7561","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:kubernetes:kubernetes:1.36.1:*:*:*:*:*:*:*"],"package":{"name":"kubernetes","version":"1.36.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2015-7561","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","metrics":{"baseScore":3.5,"impactScore":2.9,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2015-7561","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-7561","date":"2026-10-08","epss":0.01416,"percentile":0.71954}],"risk":0.44604,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1291963","https://github.com/kubernetes/kubernetes/pull/18909"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-7561","description":"Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image."},"relatedVulnerabilities":[]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-40164","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40164","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-40164","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40164","cwe":"CWE-328","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-40164","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-40164","cwe":"CWE-341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-40164","date":"2026-10-08","epss":0.00593,"percentile":0.46697}],"risk":0.44475,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-40164"},"relatedVulnerabilities":[{"id":"CVE-2026-40164","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40164","cwe":"CWE-328","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-40164","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-40164","cwe":"CWE-341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-40164","date":"2026-10-08","epss":0.00593,"percentile":0.46697}],"urls":["https://github.com/jqlang/jq/commit/0c7d133c3c7e37c00b6d46b658a02244fdd3c784","https://github.com/jqlang/jq/security/advisories/GHSA-wwj8-gxm6-jc29","https://access.redhat.com/errata/RHSA-2026:16252","https://access.redhat.com/errata/RHSA-2026:16692","https://access.redhat.com/errata/RHSA-2026:16693","https://access.redhat.com/errata/RHSA-2026:18040","https://access.redhat.com/errata/RHSA-2026:18042","https://access.redhat.com/errata/RHSA-2026:18043","https://access.redhat.com/errata/RHSA-2026:18044","https://access.redhat.com/errata/RHSA-2026:18045","https://access.redhat.com/errata/RHSA-2026:18046","https://access.redhat.com/errata/RHSA-2026:18047","https://access.redhat.com/errata/RHSA-2026:18048","https://access.redhat.com/errata/RHSA-2026:19151","https://access.redhat.com/errata/RHSA-2026:19365","https://access.redhat.com/errata/RHSA-2026:23233","https://access.redhat.com/errata/RHSA-2026:23245","https://access.redhat.com/errata/RHSA-2026:25044","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:25181","https://access.redhat.com/errata/RHSA-2026:26528","https://access.redhat.com/errata/RHSA-2026:26542","https://access.redhat.com/errata/RHSA-2026:28887","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:34098","https://access.redhat.com/errata/RHSA-2026:8579","https://access.redhat.com/security/cve/CVE-2026-40164","https://bugzilla.redhat.com/show_bug.cgi?id=2458084","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40164.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40164","description":"jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSON object (~100 KB) where all keys hashed to the same bucket, hash table lookups degraded from O(1) to O(n), turning any jq expression into an O(n²) operation and causing significant CPU exhaustion. This affected common jq use cases such as CI/CD pipelines, web services, and data processing scripts, and was far more practical to exploit than existing heap overflow issues since it required only a small payload. This issue has been patched in commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5037","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5037","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"risk":0.4432500000000001,"urls":["https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/783621","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname.\n\nWith a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."},"relatedVulnerabilities":[{"id":"CVE-2026-27145","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"urls":["https://go.dev/cl/783621","https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5037","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:29980","https://access.redhat.com/errata/RHSA-2026:29981","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46394","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49705","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:49729","https://access.redhat.com/errata/RHSA-2026:49744","https://access.redhat.com/errata/RHSA-2026:49765","https://access.redhat.com/errata/RHSA-2026:49770","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:52946","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53416","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54427","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55899","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59556","https://access.redhat.com/errata/RHSA-2026:59557","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60386","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60388","https://access.redhat.com/errata/RHSA-2026:60390","https://access.redhat.com/errata/RHSA-2026:60391","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:63016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68335","https://access.redhat.com/security/cve/CVE-2026-27145","https://bugzilla.redhat.com/show_bug.cgi?id=2484207","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27145","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5038","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5038","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"risk":0.42,"urls":["https://go.dev/cl/774481","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79217","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-42504","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"urls":["https://go.dev/cl/774481","https://go.dev/issue/79217","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5038"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42504","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-32316","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32316","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-32316","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32316","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32316","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32316","date":"2026-10-08","epss":0.00486,"percentile":0.39891}],"risk":0.3645,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-32316"},"relatedVulnerabilities":[{"id":"CVE-2026-32316","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32316","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32316","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32316","date":"2026-10-08","epss":0.00486,"percentile":0.39891}],"urls":["https://github.com/jqlang/jq/commit/e47e56d226519635768e6aab2f38f0ab037c09e5","https://github.com/jqlang/jq/security/advisories/GHSA-q3h9-m34w-h76f"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32316","description":"jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer overflow classified as CWE-190 (Integer Overflow) leading to CWE-122 (Heap-based Buffer Overflow). Any system evaluating untrusted jq queries is affected, as an attacker can crash the process or potentially achieve further exploitation through heap corruption by crafting queries that produce extremely large strings. The root cause is the absence of string size bounds checking, unlike arrays and objects which already have size limits. The issue has been addressed in commit e47e56d226519635768e6aab2f38f0ab037c09e5."}]},{"artifact":{"id":"117b2eeb5b4df624","cpes":["cpe:2.3:a:golang:text:v0.33.0:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.33.0","type":"go-module","version":"v0.33.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.39.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5970","versionConstraint":"<0.39.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.33.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5970","fix":{"state":"fixed","versions":["0.39.0"],"available":[{"date":"2026-06-30","kind":"release","version":"0.39.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56852","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56852","date":"2026-10-08","epss":0.00475,"percentile":0.39076}],"risk":0.35624999999999996,"urls":["https://go.dev/cl/794100"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80142","description":"A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-56852","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56852","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56852","date":"2026-10-08","epss":0.00475,"percentile":0.39076}],"urls":["https://go.dev/cl/794100","https://go.dev/issue/80142","https://pkg.go.dev/vuln/GO-2026-5970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56852","description":"A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63074"},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63074"},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63074"},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"eb222fe89d397776","cpes":["cpe:2.3:a:zlib:zlib:1.3.2-r0:*:*:*:*:*:*:*"],"name":"zlib","purl":"pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.3.2-r0","language":"","licenses":["Zlib"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libz.so.1"},{"path":"/usr/lib/libz.so.1.3.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"zlib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"fixed","versions":["1.3.2-r1"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.3.2-r1"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5cv4-jp36-h3mw","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-5cv4-jp36-h3mw","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-07-02","kind":"first-observed","version":"0.55.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25680","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25680","date":"2026-10-08","epss":0.0046,"percentile":0.37848}],"risk":0.26449999999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-25680","https://go.dev/cl/781702","https://go.dev/issue/79573","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5028","https://go.googlesource.com/net/+/08be507abce89191d78cd49da60f4501fc910472","https://go.googlesource.com/net/+/refs/tags/v0.55.0"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5cv4-jp36-h3mw","description":"Go Net HTML parser is vulnerable to denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-25680","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25680","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25680","date":"2026-10-08","epss":0.0046,"percentile":0.37848}],"urls":["https://go.dev/cl/781702","https://go.dev/issue/79573","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5028"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25680","description":"Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5039","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5039","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"risk":0.21218,"urls":["https://go.dev/cl/777060","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79346","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."},"relatedVulnerabilities":[{"id":"CVE-2026-42507","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"urls":["https://go.dev/cl/777060","https://go.dev/issue/79346","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5039"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42507","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-75803"},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-75803"},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"3.5.8-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.8-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.5.8-r0"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"3.5.8-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-75803"},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5856","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5856","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"risk":0.19673,"urls":["https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/775960","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."},"relatedVulnerabilities":[{"id":"CVE-2026-42505","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"urls":["https://go.dev/cl/775960","https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-5856"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42505","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5025","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5025","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42506","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42506","date":"2026-10-08","epss":0.00333,"percentile":0.2444}],"risk":0.18481499999999998,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781700"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79571","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-42506","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42506","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42506","date":"2026-10-08","epss":0.00333,"percentile":0.2444}],"urls":["https://go.dev/cl/781700","https://go.dev/issue/79571","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42506","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33948","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33948","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-33948","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33948","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33948","cwe":"CWE-170","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33948","date":"2026-10-08","epss":0.00349,"percentile":0.26398}],"risk":0.179735,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-33948"},"relatedVulnerabilities":[{"id":"CVE-2026-33948","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33948","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33948","cwe":"CWE-170","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33948","date":"2026-10-08","epss":0.00349,"percentile":0.26398}],"urls":["https://github.com/jqlang/jq/commit/6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b","https://github.com/jqlang/jq/security/advisories/GHSA-32cx-cvvh-2wj9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33948","description":"jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4970","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4970","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"risk":0.17748,"urls":["https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://go.dev/cl/797880"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79005","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /.\n\nFor example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."},"relatedVulnerabilities":[{"id":"CVE-2026-39822","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"urls":["https://go.dev/cl/797880","https://go.dev/issue/79005","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-4970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39822","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."}]},{"artifact":{"id":"90de48f0110b1d66","cpes":["cpe:2.3:a:opentelemetry:opentelemetry:v1.41.0:*:*:*:*:go:*:*"],"name":"go.opentelemetry.io/otel","purl":"pkg:golang/go.opentelemetry.io/otel@v1.41.0","type":"go-module","version":"v1.41.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.42.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5158","versionConstraint":">=1.41.0,<1.42.0||>=1.43.0,<1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel","version":"v1.41.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5158","fix":{"state":"fixed","versions":["1.42.0","1.44.0"],"available":[{"date":"2026-03-06","kind":"release","version":"1.42.0"},{"date":"2026-05-27","kind":"release","version":"1.44.0"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41178","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41178","date":"2026-10-08","epss":0.00336,"percentile":0.24903}],"risk":0.17304000000000003,"urls":["https://github.com/open-telemetry/opentelemetry-go/pull/7880"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835","description":"Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel"},"relatedVulnerabilities":[{"id":"CVE-2026-41178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41178","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41178","date":"2026-10-08","epss":0.00336,"percentile":0.24903}],"urls":["https://github.com/open-telemetry/opentelemetry-go/pull/7880","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41178","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue."},{"id":"GHSA-5wrp-cwcj-q835","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41178","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41178","date":"2026-10-08","epss":0.00336,"percentile":0.24903}],"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835","https://nvd.nist.gov/vuln/detail/CVE-2026-41178","https://github.com/open-telemetry/opentelemetry-go/pull/7880"],"severity":"Medium","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-5wrp-cwcj-q835","description":"opentelemetry-go's baggage parsing no longer caps raw header length"}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"fef07e9c95ea2bda","cpes":["cpe:2.3:a:busybox:busybox:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox","purl":"pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/busybox"},{"path":"/etc"},{"path":"/etc/securetty"},{"path":"/etc/busybox-paths.d"},{"path":"/etc/busybox-paths.d/busybox"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/acpid"},{"path":"/etc/network"},{"path":"/etc/network/if-down.d"},{"path":"/etc/network/if-post-down.d"},{"path":"/etc/network/if-post-up.d"},{"path":"/etc/network/if-pre-down.d"},{"path":"/etc/network/if-pre-up.d"},{"path":"/etc/network/if-up.d"},{"path":"/etc/network/if-up.d/dad"},{"path":"/etc/udhcpc"},{"path":"/etc/udhcpc/udhcpc.conf"},{"path":"/sbin"},{"path":"/usr"},{"path":"/usr/sbin"},{"path":"/usr/share"},{"path":"/usr/share/udhcpc"},{"path":"/usr/share/udhcpc/default.script"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"915155597fcdee9a","cpes":["cpe:2.3:a:busybox-binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox-binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox-binsh","purl":"pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64&distro=alpine-3.24.1&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/sh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"8a9ef44e1018f213","cpes":["cpe:2.3:a:ssl-client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl-client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl_client:1.37.0-r31:*:*:*:*:*:*:*"],"name":"ssl_client","purl":"pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64&distro=alpine-3.24.1&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssl_client"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35189","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35189","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35189","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5030","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5030","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27136","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27136","date":"2026-10-08","epss":0.00223,"percentile":0.11872}],"risk":0.12376500000000001,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781685"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79575","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-27136","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27136","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27136","date":"2026-10-08","epss":0.00223,"percentile":0.11872}],"urls":["https://go.dev/cl/781685","https://go.dev/issue/79575","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5030"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27136","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5027","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5027","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42502","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42502","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"risk":0.12376500000000001,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781701"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79572","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-42502","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42502","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42502","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"urls":["https://go.dev/cl/781701","https://go.dev/issue/79572","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5027"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42502","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5029","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5029","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25681","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25681","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"risk":0.12376500000000001,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781703"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79574","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-25681","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25681","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25681","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"urls":["https://go.dev/cl/781703","https://go.dev/issue/79574","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5029"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25681","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-49839","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-49839","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-49839","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"risk":0.12045,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-49839"},"relatedVulnerabilities":[{"id":"CVE-2026-49839","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49839","description":"jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35191","versionConstraint":">= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35191","versionConstraint":">= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35191","versionConstraint":">= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"117b2eeb5b4df624","cpes":["cpe:2.3:a:golang:text:v0.33.0:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.33.0","type":"go-module","version":"v0.33.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.41.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6629","versionConstraint":"<0.41.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.33.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6629","fix":{"state":"fixed","versions":["0.41.0"],"available":[{"date":"2026-08-11","kind":"release","version":"0.41.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56851","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56851","date":"2026-10-08","epss":0.00155,"percentile":0.04088}],"risk":0.11624999999999999,"urls":["https://go.dev/issue/80112"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/793360","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-56851","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56851","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56851","date":"2026-10-08","epss":0.00155,"percentile":0.04088}],"urls":["https://go.dev/cl/793360","https://go.dev/issue/80112","https://pkg.go.dev/vuln/GO-2026-6629"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56851","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."}]},{"artifact":{"id":"28598ebb92f073ad","cpes":["cpe:2.3:a:golang:text:v0.39.0:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.39.0","type":"go-module","version":"v0.39.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:UbZz4pLOvn600D6Oh6GGEI6VAmndrEBLv8/6BEXzyus=","mainModule":"github.com/aquasecurity/kube-bench","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.41.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6629","versionConstraint":"<0.41.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.39.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6629","fix":{"state":"fixed","versions":["0.41.0"],"available":[{"date":"2026-08-11","kind":"release","version":"0.41.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56851","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56851","date":"2026-10-08","epss":0.00155,"percentile":0.04088}],"risk":0.11624999999999999,"urls":["https://go.dev/issue/80112"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/793360","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-56851","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56851","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56851","date":"2026-10-08","epss":0.00155,"percentile":0.04088}],"urls":["https://go.dev/cl/793360","https://go.dev/issue/80112","https://pkg.go.dev/vuln/GO-2026-6629"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56851","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75805","versionConstraint":">= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75805","versionConstraint":">= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75805","versionConstraint":">= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54875","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54875","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54875","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"},"relatedVulnerabilities":[]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33947","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33947","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-33947","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33947","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33947","date":"2026-10-08","epss":0.00176,"percentile":0.06564}],"risk":0.09240000000000001,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-33947"},"relatedVulnerabilities":[{"id":"CVE-2026-33947","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33947","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33947","date":"2026-10-08","epss":0.00176,"percentile":0.06564}],"urls":["https://github.com/jqlang/jq/commit/fb59f1491058d58bdc3e8dd28f1773d1ac690a1f","https://github.com/jqlang/jq/security/advisories/GHSA-xwrw-4f8h-rjvg","http://www.openwall.com/lists/oss-security/2026/04/16/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33947","description":"jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-39956","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-39956","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-39956","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39956","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-39956","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-39956","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39956","date":"2026-10-08","epss":0.00165,"percentile":0.05161}],"risk":0.09157499999999999,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-39956"},"relatedVulnerabilities":[{"id":"CVE-2026-39956","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39956","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-39956","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-39956","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39956","date":"2026-10-08","epss":0.00165,"percentile":0.05161}],"urls":["https://github.com/jqlang/jq/commit/fdf8ef0f0810e3d365cdd5160de43db46f57ed03","https://github.com/jqlang/jq/security/advisories/GHSA-6gc3-3g9p-xx28"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39956","description":"jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are stripped in release builds compiled with -DNDEBUG. This allows an attacker to crash jq trivially with input like _strindices(0), and by crafting a numeric value whose IEEE-754 bit pattern maps to a chosen pointer, achieve a controlled pointer dereference and limited memory read/probe primitive. Any deployment that evaluates untrusted jq filters against a release build is vulnerable. This issue has been patched in commit fdf8ef0f0810e3d365cdd5160de43db46f57ed03, which is part of version 1.8.2."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54872","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54872","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54872","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."},"relatedVulnerabilities":[]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41256","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41256","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-41256","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.082425,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-41256"},"relatedVulnerabilities":[{"id":"CVE-2026-41256","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41256","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-40612","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"risk":0.0819,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-40612"},"relatedVulnerabilities":[{"id":"CVE-2026-40612","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40612","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-44777","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44777","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-44777","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.0819,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-44777"},"relatedVulnerabilities":[{"id":"CVE-2026-44777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44777","description":"jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-47770","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47770","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-47770","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.0819,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-47770"},"relatedVulnerabilities":[{"id":"CVE-2026-47770","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47770","description":"jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"e23c248c64dfa980","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-77696","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."},"relatedVulnerabilities":[]},{"artifact":{"id":"7de879f497a38539","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.7-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1&upstream=openssl","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-77696","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."},"relatedVulnerabilities":[]},{"artifact":{"id":"6d60a37544bb98cc","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.7-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"3.5.7-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-77696","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.7:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.7-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."},"relatedVulnerabilities":[]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43894","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43894","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-43894","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"risk":0.080325,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-43894"},"relatedVulnerabilities":[{"id":"CVE-2026-43894","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43894","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit)."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43896","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43896","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-43896","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"risk":0.07875,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-43896"},"relatedVulnerabilities":[{"id":"CVE-2026-43896","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43896","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54679","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54679","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-54679","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"risk":0.077175,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-54679"},"relatedVulnerabilities":[{"id":"CVE-2026-54679","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54679","description":"jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41257","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41257","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-41257","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"risk":0.07192499999999999,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-41257"},"relatedVulnerabilities":[{"id":"CVE-2026-41257","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41257","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets."}]},{"artifact":{"id":"87b4ab38da92efb1","cpes":["cpe:2.3:a:jq:jq:1.8.1-r0:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:apk/alpine/jq@1.8.1-r0?arch=x86_64&distro=alpine-3.24.1","type":"apk","version":"1.8.1-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/jq"},{"path":"/usr/lib"},{"path":"/usr/lib/libjq.so.1"},{"path":"/usr/lib/libjq.so.1.0.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"jq"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43895","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.8.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43895","versionConstraint":"< 1.8.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.1"},"package":{"name":"jq","version":"1.8.1-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-43895","fix":{"state":"fixed","versions":["1.8.2-r0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.8.2-r0"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"risk":0.07097,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-43895"},"relatedVulnerabilities":[{"id":"CVE-2026-43895","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43895","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens."}]},{"artifact":{"id":"f3ac6aa4fd700772","cpes":["cpe:2.3:a:golang:x\\/sys:v0.40.0:*:*:*:*:*:*:*"],"name":"golang.org/x/sys","purl":"pkg:golang/golang.org/x/sys@v0.40.0","type":"go-module","version":"v0.40.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.44.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5024","versionConstraint":"<0.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/sys","version":"v0.40.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5024","fix":{"state":"fixed","versions":["0.44.0"],"available":[{"date":"2026-04-23","kind":"release","version":"0.44.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"risk":0.04976999999999999,"urls":["https://go.dev/cl/770080","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78916","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."},"relatedVulnerabilities":[{"id":"CVE-2026-39824","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"urls":["https://go.dev/cl/770080","https://go.dev/issue/78916","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg","https://pkg.go.dev/vuln/GO-2026-5024"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39824","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"d3c8040a6685b36b","cpes":["cpe:2.3:a:golang:networking:v0.49.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.49.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.49.0","type":"go-module","version":"v0.49.0","language":"go","licenses":[],"metadata":{"mainModule":"k8s.io/kubernetes","architecture":"amd64","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.49.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]},{"artifact":{"id":"b58e52d9cb84adfc","cpes":["cpe:2.3:a:golang:networking:v0.56.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.56.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.56.0","type":"go-module","version":"v0.56.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=","mainModule":"github.com/aquasecurity/kube-bench","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.56.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"b58e52d9cb84adfc","cpes":["cpe:2.3:a:golang:networking:v0.56.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.56.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.56.0","type":"go-module","version":"v0.56.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=","mainModule":"github.com/aquasecurity/kube-bench","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.56.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"b58e52d9cb84adfc","cpes":["cpe:2.3:a:golang:networking:v0.56.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.56.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.56.0","type":"go-module","version":"v0.56.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=","mainModule":"github.com/aquasecurity/kube-bench","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.56.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"b58e52d9cb84adfc","cpes":["cpe:2.3:a:golang:networking:v0.56.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.56.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.56.0","type":"go-module","version":"v0.56.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=","mainModule":"github.com/aquasecurity/kube-bench","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.56.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"b58e52d9cb84adfc","cpes":["cpe:2.3:a:golang:networking:v0.56.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.56.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.56.0","type":"go-module","version":"v0.56.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=","mainModule":"github.com/aquasecurity/kube-bench","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.56.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"48b14470e7a2a38a","cpes":["cpe:2.3:a:golang:go:1.26.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.3","type":"go-module","version":"go1.26.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.3"},"locations":[{"path":"/usr/bin/kubectl","layerID":"sha256:66720efd377e2e6c7e25328558a379e1b6b8fa82f86289e39697afbc4ec3c8b8","accessPath":"/usr/bin/kubectl","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"f391e5a44379bda5","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/usr/local/bin/kube-bench","layerID":"sha256:028a0ccfcccfde14b1ae50c4c855c17128c7c65dd98c946c2fe79fe6bea714b5","accessPath":"/usr/local/bin/kube-bench","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:37:55.246Z","grype_db_version":"2026-10-09T06:32:32.000Z"}