{"grype_matches":[{"artifact":{"id":"28ad8f509ca8a34a","cpes":["cpe:2.3:a:piotr_dabkowski_project:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piotr_dabkowski_project:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piotr_dabkowskiproject:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piotr_dabkowskiproject:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piotr_dabkowski_project:js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piodrus_project:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piodrus_project:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piotr_dabkowski:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piotr_dabkowski:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piotr_dabkowskiproject:js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piodrusproject:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piodrusproject:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:python-js2py:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:python-js2py:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:python_js2py:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:python_js2py:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piodrus_project:js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piotr_dabkowski:js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piodrus:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piodrus:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piodrusproject:js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:python:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:python:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:js2py:python-js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:js2py:python_js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:python-js2py:js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:python_js2py:js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:piodrus:js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:python:js2py:0.74:*:*:*:*:*:*:*","cpe:2.3:a:js2py:js2py:0.74:*:*:*:*:*:*:*"],"name":"js2py","purl":"pkg:pypi/js2py@0.74","type":"python","version":"0.74","language":"python","licenses":["MIT"],"locations":[{"path":"/app/bazarr/bin/libs/Js2Py-0.74.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/Js2Py-0.74.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/Js2Py-0.74.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/Js2Py-0.74.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/app/bazarr/bin/libs/Js2Py-0.74.dist-info/top_level.txt","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/Js2Py-0.74.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h95x-26f3-88hr","versionConstraint":"<=0.74 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"js2py","version":"0.74"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-h95x-26f3-88hr","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28397","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28397","date":"2026-10-08","epss":0.04548,"percentile":0.91336}],"risk":3.6952499999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-28397","https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape","https://github.com/PiotrDabkowski/Js2Py/pull/323","https://github.com/Marven11"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h95x-26f3-88hr","description":"js2py allows remote code execution"},"relatedVulnerabilities":[{"id":"CVE-2024-28397","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28397","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28397","date":"2026-10-08","epss":0.04548,"percentile":0.91336}],"urls":["https://github.com/Marven11","https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28397","description":"An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call."}]},{"artifact":{"id":"4db35769138b374b","cpes":["cpe:2.3:a:gnome:glib:2.86.3-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.86.3-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.86.3-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"2.86.3-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8600.3"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8600.3"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8600.3"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8600.3"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8600.3"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8600.3"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58016","versionConstraint":"< 2.88.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.86.3:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.86.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58016","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"risk":0.8589450000000001,"urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4db35769138b374b","cpes":["cpe:2.3:a:gnome:glib:2.86.3-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.86.3-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.86.3-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"2.86.3-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8600.3"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8600.3"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8600.3"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8600.3"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8600.3"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8600.3"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58015","versionConstraint":"< 2.88.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.86.3:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.86.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58015","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"risk":0.6446799999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."},"relatedVulnerabilities":[]},{"artifact":{"id":"4db35769138b374b","cpes":["cpe:2.3:a:gnome:glib:2.86.3-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.86.3-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.86.3-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"2.86.3-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8600.3"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8600.3"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8600.3"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8600.3"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8600.3"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8600.3"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58010","versionConstraint":"< 2.86.5||= 2.88.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.86.3:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.86.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58010","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6333524999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"4db35769138b374b","cpes":["cpe:2.3:a:gnome:glib:2.86.3-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.86.3-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.86.3-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"2.86.3-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8600.3"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8600.3"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8600.3"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8600.3"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8600.3"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8600.3"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58012","versionConstraint":"< 2.86.5||= 2.88.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.86.3:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.86.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58012","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6333524999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"4db35769138b374b","cpes":["cpe:2.3:a:gnome:glib:2.86.3-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.86.3-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.86.3-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"2.86.3-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8600.3"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8600.3"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8600.3"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8600.3"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8600.3"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8600.3"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58013","versionConstraint":"< 2.88.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.86.3:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.86.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58013","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6333524999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4db35769138b374b","cpes":["cpe:2.3:a:gnome:glib:2.86.3-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.86.3-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.86.3-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"2.86.3-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8600.3"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8600.3"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8600.3"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8600.3"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8600.3"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8600.3"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58011","versionConstraint":"< 2.86.5||= 2.88.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.86.3:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.86.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58011","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"risk":0.5916,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"4db35769138b374b","cpes":["cpe:2.3:a:gnome:glib:2.86.3-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.86.3-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.86.3-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"2.86.3-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8600.3"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8600.3"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8600.3"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8600.3"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8600.3"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8600.3"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58014","versionConstraint":"< 2.88.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.86.3:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.86.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58014","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"risk":0.5577449999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73851","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"f94b9b7cafe48a8a","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r1:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r1:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"1.7.19-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-67215","versionConstraint":"<= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-67215","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67215","cwe":"CWE-674","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67215","date":"2026-10-08","epss":0.007,"percentile":0.51693}],"risk":0.546,"urls":["https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L253-L261","https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON_Utils.c#L906-L940","https://joshua.hu/cjson-json-parser-cve-vulnerabilities","https://www.vulncheck.com/advisories/cjson-json-patch-copy-add-uncontrolled-recursion-stack-exhaustion"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67215","description":"cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"f94b9b7cafe48a8a","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r1:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r1:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"1.7.19-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-67216","versionConstraint":"<= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-67216","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67216","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67216","date":"2026-10-08","epss":0.00645,"percentile":0.49346}],"risk":0.474075,"urls":["https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L3057-L3180","https://joshua.hu/cjson-json-parser-cve-vulnerabilities","https://www.vulncheck.com/advisories/cjson-cjson-compare-exponential-complexity-denial-of-service"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67216","description":"cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition."},"relatedVulnerabilities":[]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59843","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59843","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59843","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59843","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59843","date":"2026-10-08","epss":0.00725,"percentile":0.52664}],"risk":0.416875,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59843","https://bugzilla.redhat.com/show_bug.cgi?id=2498176"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59843","description":"A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59851","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59851","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59851","cwe":"CWE-863","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59851","date":"2026-10-08","epss":0.00489,"percentile":0.40155}],"risk":0.39853500000000003,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/security/cve/CVE-2026-59851","https://bugzilla.redhat.com/show_bug.cgi?id=2498184"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59851","description":"A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59844","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59844","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59844","cwe":"CWE-789","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59844","date":"2026-10-08","epss":0.00567,"percentile":0.45263}],"risk":0.32602499999999995,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59844","https://bugzilla.redhat.com/show_bug.cgi?id=2498177"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59844","description":"A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd4957c541e1f4e6","cpes":["cpe:2.3:a:isaac_muse_\\<isaac_muse_project:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse_project:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_museproject:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_museproject:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse_project:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac-muse-\\<isaac-muse:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac-muse-\\<isaac-muse:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_museproject:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python-soupsieve:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python-soupsieve:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python_soupsieve:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python_soupsieve:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac-muse-\\<isaac-muse:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python-soupsieve:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python_soupsieve:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:soupsieve:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:soupsieve:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:soupsieve:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python:soupsieve:2.8.4:*:*:*:*:*:*:*"],"name":"soupsieve","purl":"pkg:pypi/soupsieve@2.8.4","type":"python","version":"2.8.4","language":"python","licenses":["MIT"],"locations":[{"path":"/app/bazarr/bin/libs/soupsieve-2.8.4.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/soupsieve-2.8.4.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/soupsieve-2.8.4.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/soupsieve-2.8.4.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j934-xhv5-fg8f","versionConstraint":"<2.9.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"soupsieve","version":"2.8.4"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-j934-xhv5-fg8f","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85999","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-85999","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-85999","date":"2026-10-08","epss":0.00609,"percentile":0.47524}],"risk":0.313635,"urls":["https://github.com/facelessuser/soupsieve/security/advisories/GHSA-j934-xhv5-fg8f","https://nvd.nist.gov/vuln/detail/CVE-2026-85999","https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda","https://github.com/facelessuser/soupsieve/releases/tag/2.9"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j934-xhv5-fg8f","description":"Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)"},"relatedVulnerabilities":[{"id":"CVE-2026-85999","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85999","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-85999","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-85999","date":"2026-10-08","epss":0.00609,"percentile":0.47524}],"urls":["https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda","https://github.com/facelessuser/soupsieve/releases/tag/2.9","https://github.com/facelessuser/soupsieve/security/advisories/GHSA-j934-xhv5-fg8f"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85999","description":"Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every starting offset. An attacker-controlled valid selector containing a long internal whitespace run, or a selector containing a long CSS comment run followed by another token, causes quadratic CPU work before tokenization. User-controlled selectors can reach the path through soupsieve.compile() and BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. This root cause is separate from the IDENTIFIER and VALUE backtracking vulnerability because the cost occurs in RE_WS_END.search during trimming rather than token matching. The resulting CPU consumption can hold the Python GIL, exhaust workers, and stall a service without causing memory corruption or code execution. The issue is fixed in version 2.9."}]},{"artifact":{"id":"cd4957c541e1f4e6","cpes":["cpe:2.3:a:isaac_muse_\\<isaac_muse_project:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse_project:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_museproject:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_museproject:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse_project:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac-muse-\\<isaac-muse:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac-muse-\\<isaac-muse:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_museproject:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python-soupsieve:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python-soupsieve:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python_soupsieve:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python_soupsieve:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac-muse-\\<isaac-muse:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:isaac_muse_\\<isaac_muse:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python-soupsieve:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python_soupsieve:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:soupsieve:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:soupsieve:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python:python-soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python:python_soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:soupsieve:soupsieve:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:python:soupsieve:2.8.4:*:*:*:*:*:*:*"],"name":"soupsieve","purl":"pkg:pypi/soupsieve@2.8.4","type":"python","version":"2.8.4","language":"python","licenses":["MIT"],"locations":[{"path":"/app/bazarr/bin/libs/soupsieve-2.8.4.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/soupsieve-2.8.4.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/soupsieve-2.8.4.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/soupsieve-2.8.4.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gjv8-xp57-g29c","versionConstraint":"<2.9.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"soupsieve","version":"2.8.4"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-gjv8-xp57-g29c","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86000","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-86000","cwe":"CWE-1333","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-86000","date":"2026-10-08","epss":0.00609,"percentile":0.47523}],"risk":0.313635,"urls":["https://github.com/facelessuser/soupsieve/security/advisories/GHSA-gjv8-xp57-g29c","https://nvd.nist.gov/vuln/detail/CVE-2026-86000","https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef","https://github.com/facelessuser/soupsieve/releases/tag/2.9"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gjv8-xp57-g29c","description":"Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns"},"relatedVulnerabilities":[{"id":"CVE-2026-86000","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86000","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-86000","cwe":"CWE-1333","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-86000","date":"2026-10-08","epss":0.00609,"percentile":0.47523}],"urls":["https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef","https://github.com/facelessuser/soupsieve/releases/tag/2.9","https://github.com/facelessuser/soupsieve/security/advisories/GHSA-gjv8-xp57-g29c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86000","description":"Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled selector contains a long identifier or unquoted attribute-value run followed by input that makes the overall match fail, the regular expression engine explores quadratically many splits between the overlapping groups. User-controlled selectors can reach this path through soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. The resulting CPU consumption can hold the Python GIL, exhaust application workers, and stall a service; successful plain identifier matches are linear, and the issue does not cause memory corruption or code execution. The issue is fixed in version 2.9."}]},{"artifact":{"id":"09c24a4342b1cfdb","cpes":["cpe:2.3:a:python-software-foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.12.15-r0:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:apk/alpine/python3@3.12.15-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"3.12.15-r0","language":"","licenses":["PSF-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/2to3"},{"path":"/usr/bin/2to3-3.12"},{"path":"/usr/bin/pydoc3"},{"path":"/usr/bin/pydoc3.12"},{"path":"/usr/bin/python"},{"path":"/usr/bin/python3"},{"path":"/usr/bin/python3.12"},{"path":"/usr/include"},{"path":"/usr/include/python3.12"},{"path":"/usr/include/python3.12/pyconfig.h"},{"path":"/usr/lib"},{"path":"/usr/lib/libpython3.12.so.1.0"},{"path":"/usr/lib/libpython3.so"},{"path":"/usr/lib/python3.12"},{"path":"/usr/lib/python3.12/EXTERNALLY-MANAGED"},{"path":"/usr/lib/python3.12/LICENSE.txt"},{"path":"/usr/lib/python3.12/__future__.py"},{"path":"/usr/lib/python3.12/__hello__.py"},{"path":"/usr/lib/python3.12/_aix_support.py"},{"path":"/usr/lib/python3.12/_collections_abc.py"},{"path":"/usr/lib/python3.12/_compat_pickle.py"},{"path":"/usr/lib/python3.12/_compression.py"},{"path":"/usr/lib/python3.12/_markupbase.py"},{"path":"/usr/lib/python3.12/_osx_support.py"},{"path":"/usr/lib/python3.12/_py_abc.py"},{"path":"/usr/lib/python3.12/_pydatetime.py"},{"path":"/usr/lib/python3.12/_pydecimal.py"},{"path":"/usr/lib/python3.12/_pyio.py"},{"path":"/usr/lib/python3.12/_pylong.py"},{"path":"/usr/lib/python3.12/_sitebuiltins.py"},{"path":"/usr/lib/python3.12/_strptime.py"},{"path":"/usr/lib/python3.12/_sysconfigdata__linux_x86_64-linux-musl.py"},{"path":"/usr/lib/python3.12/_threading_local.py"},{"path":"/usr/lib/python3.12/_weakrefset.py"},{"path":"/usr/lib/python3.12/abc.py"},{"path":"/usr/lib/python3.12/aifc.py"},{"path":"/usr/lib/python3.12/antigravity.py"},{"path":"/usr/lib/python3.12/argparse.py"},{"path":"/usr/lib/python3.12/ast.py"},{"path":"/usr/lib/python3.12/base64.py"},{"path":"/usr/lib/python3.12/bdb.py"},{"path":"/usr/lib/python3.12/bisect.py"},{"path":"/usr/lib/python3.12/bz2.py"},{"path":"/usr/lib/python3.12/cProfile.py"},{"path":"/usr/lib/python3.12/calendar.py"},{"path":"/usr/lib/python3.12/cgi.py"},{"path":"/usr/lib/python3.12/cgitb.py"},{"path":"/usr/lib/python3.12/chunk.py"},{"path":"/usr/lib/python3.12/cmd.py"},{"path":"/usr/lib/python3.12/code.py"},{"path":"/usr/lib/python3.12/codecs.py"},{"path":"/usr/lib/python3.12/codeop.py"},{"path":"/usr/lib/python3.12/colorsys.py"},{"path":"/usr/lib/python3.12/compileall.py"},{"path":"/usr/lib/python3.12/configparser.py"},{"path":"/usr/lib/python3.12/contextlib.py"},{"path":"/usr/lib/python3.12/contextvars.py"},{"path":"/usr/lib/python3.12/copy.py"},{"path":"/usr/lib/python3.12/copyreg.py"},{"path":"/usr/lib/python3.12/crypt.py"},{"path":"/usr/lib/python3.12/csv.py"},{"path":"/usr/lib/python3.12/dataclasses.py"},{"path":"/usr/lib/python3.12/datetime.py"},{"path":"/usr/lib/python3.12/decimal.py"},{"path":"/usr/lib/python3.12/difflib.py"},{"path":"/usr/lib/python3.12/dis.py"},{"path":"/usr/lib/python3.12/doctest.py"},{"path":"/usr/lib/python3.12/enum.py"},{"path":"/usr/lib/python3.12/filecmp.py"},{"path":"/usr/lib/python3.12/fileinput.py"},{"path":"/usr/lib/python3.12/fnmatch.py"},{"path":"/usr/lib/python3.12/fractions.py"},{"path":"/usr/lib/python3.12/ftplib.py"},{"path":"/usr/lib/python3.12/functools.py"},{"path":"/usr/lib/python3.12/genericpath.py"},{"path":"/usr/lib/python3.12/getopt.py"},{"path":"/usr/lib/python3.12/getpass.py"},{"path":"/usr/lib/python3.12/gettext.py"},{"path":"/usr/lib/python3.12/glob.py"},{"path":"/usr/lib/python3.12/graphlib.py"},{"path":"/usr/lib/python3.12/gzip.py"},{"path":"/usr/lib/python3.12/hashlib.py"},{"path":"/usr/lib/python3.12/heapq.py"},{"path":"/usr/lib/python3.12/hmac.py"},{"path":"/usr/lib/python3.12/imaplib.py"},{"path":"/usr/lib/python3.12/imghdr.py"},{"path":"/usr/lib/python3.12/inspect.py"},{"path":"/usr/lib/python3.12/io.py"},{"path":"/usr/lib/python3.12/ipaddress.py"},{"path":"/usr/lib/python3.12/keyword.py"},{"path":"/usr/lib/python3.12/linecache.py"},{"path":"/usr/lib/python3.12/locale.py"},{"path":"/usr/lib/python3.12/lzma.py"},{"path":"/usr/lib/python3.12/mailbox.py"},{"path":"/usr/lib/python3.12/mailcap.py"},{"path":"/usr/lib/python3.12/mimetypes.py"},{"path":"/usr/lib/python3.12/modulefinder.py"},{"path":"/usr/lib/python3.12/netrc.py"},{"path":"/usr/lib/python3.12/nntplib.py"},{"path":"/usr/lib/python3.12/ntpath.py"},{"path":"/usr/lib/python3.12/nturl2path.py"},{"path":"/usr/lib/python3.12/numbers.py"},{"path":"/usr/lib/python3.12/opcode.py"},{"path":"/usr/lib/python3.12/operator.py"},{"path":"/usr/lib/python3.12/optparse.py"},{"path":"/usr/lib/python3.12/os.py"},{"path":"/usr/lib/python3.12/pathlib.py"},{"path":"/usr/lib/python3.12/pdb.py"},{"path":"/usr/lib/python3.12/pickle.py"},{"path":"/usr/lib/python3.12/pickletools.py"},{"path":"/usr/lib/python3.12/pipes.py"},{"path":"/usr/lib/python3.12/pkgutil.py"},{"path":"/usr/lib/python3.12/platform.py"},{"path":"/usr/lib/python3.12/plistlib.py"},{"path":"/usr/lib/python3.12/poplib.py"},{"path":"/usr/lib/python3.12/posixpath.py"},{"path":"/usr/lib/python3.12/pprint.py"},{"path":"/usr/lib/python3.12/profile.py"},{"path":"/usr/lib/python3.12/pstats.py"},{"path":"/usr/lib/python3.12/pty.py"},{"path":"/usr/lib/python3.12/py_compile.py"},{"path":"/usr/lib/python3.12/pyclbr.py"},{"path":"/usr/lib/python3.12/pydoc.py"},{"path":"/usr/lib/python3.12/queue.py"},{"path":"/usr/lib/python3.12/quopri.py"},{"path":"/usr/lib/python3.12/random.py"},{"path":"/usr/lib/python3.12/reprlib.py"},{"path":"/usr/lib/python3.12/rlcompleter.py"},{"path":"/usr/lib/python3.12/runpy.py"},{"path":"/usr/lib/python3.12/sched.py"},{"path":"/usr/lib/python3.12/secrets.py"},{"path":"/usr/lib/python3.12/selectors.py"},{"path":"/usr/lib/python3.12/shelve.py"},{"path":"/usr/lib/python3.12/shlex.py"},{"path":"/usr/lib/python3.12/shutil.py"},{"path":"/usr/lib/python3.12/signal.py"},{"path":"/usr/lib/python3.12/site.py"},{"path":"/usr/lib/python3.12/smtplib.py"},{"path":"/usr/lib/python3.12/sndhdr.py"},{"path":"/usr/lib/python3.12/socket.py"},{"path":"/usr/lib/python3.12/socketserver.py"},{"path":"/usr/lib/python3.12/sre_compile.py"},{"path":"/usr/lib/python3.12/sre_constants.py"},{"path":"/usr/lib/python3.12/sre_parse.py"},{"path":"/usr/lib/python3.12/ssl.py"},{"path":"/usr/lib/python3.12/stat.py"},{"path":"/usr/lib/python3.12/statistics.py"},{"path":"/usr/lib/python3.12/string.py"},{"path":"/usr/lib/python3.12/stringprep.py"},{"path":"/usr/lib/python3.12/struct.py"},{"path":"/usr/lib/python3.12/subprocess.py"},{"path":"/usr/lib/python3.12/sunau.py"},{"path":"/usr/lib/python3.12/symtable.py"},{"path":"/usr/lib/python3.12/sysconfig.py"},{"path":"/usr/lib/python3.12/tabnanny.py"},{"path":"/usr/lib/python3.12/tarfile.py"},{"path":"/usr/lib/python3.12/telnetlib.py"},{"path":"/usr/lib/python3.12/tempfile.py"},{"path":"/usr/lib/python3.12/textwrap.py"},{"path":"/usr/lib/python3.12/this.py"},{"path":"/usr/lib/python3.12/threading.py"},{"path":"/usr/lib/python3.12/timeit.py"},{"path":"/usr/lib/python3.12/token.py"},{"path":"/usr/lib/python3.12/tokenize.py"},{"path":"/usr/lib/python3.12/trace.py"},{"path":"/usr/lib/python3.12/traceback.py"},{"path":"/usr/lib/python3.12/tracemalloc.py"},{"path":"/usr/lib/python3.12/tty.py"},{"path":"/usr/lib/python3.12/turtle.py"},{"path":"/usr/lib/python3.12/types.py"},{"path":"/usr/lib/python3.12/typing.py"},{"path":"/usr/lib/python3.12/uu.py"},{"path":"/usr/lib/python3.12/uuid.py"},{"path":"/usr/lib/python3.12/warnings.py"},{"path":"/usr/lib/python3.12/wave.py"},{"path":"/usr/lib/python3.12/weakref.py"},{"path":"/usr/lib/python3.12/webbrowser.py"},{"path":"/usr/lib/python3.12/xdrlib.py"},{"path":"/usr/lib/python3.12/zipapp.py"},{"path":"/usr/lib/python3.12/zipimport.py"},{"path":"/usr/lib/python3.12/__phello__"},{"path":"/usr/lib/python3.12/__phello__/__init__.py"},{"path":"/usr/lib/python3.12/__phello__/spam.py"},{"path":"/usr/lib/python3.12/asyncio"},{"path":"/usr/lib/python3.12/asyncio/__init__.py"},{"path":"/usr/lib/python3.12/asyncio/__main__.py"},{"path":"/usr/lib/python3.12/asyncio/base_events.py"},{"path":"/usr/lib/python3.12/asyncio/base_futures.py"},{"path":"/usr/lib/python3.12/asyncio/base_subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/base_tasks.py"},{"path":"/usr/lib/python3.12/asyncio/constants.py"},{"path":"/usr/lib/python3.12/asyncio/coroutines.py"},{"path":"/usr/lib/python3.12/asyncio/events.py"},{"path":"/usr/lib/python3.12/asyncio/exceptions.py"},{"path":"/usr/lib/python3.12/asyncio/format_helpers.py"},{"path":"/usr/lib/python3.12/asyncio/futures.py"},{"path":"/usr/lib/python3.12/asyncio/locks.py"},{"path":"/usr/lib/python3.12/asyncio/log.py"},{"path":"/usr/lib/python3.12/asyncio/mixins.py"},{"path":"/usr/lib/python3.12/asyncio/proactor_events.py"},{"path":"/usr/lib/python3.12/asyncio/protocols.py"},{"path":"/usr/lib/python3.12/asyncio/queues.py"},{"path":"/usr/lib/python3.12/asyncio/runners.py"},{"path":"/usr/lib/python3.12/asyncio/selector_events.py"},{"path":"/usr/lib/python3.12/asyncio/sslproto.py"},{"path":"/usr/lib/python3.12/asyncio/staggered.py"},{"path":"/usr/lib/python3.12/asyncio/streams.py"},{"path":"/usr/lib/python3.12/asyncio/subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/taskgroups.py"},{"path":"/usr/lib/python3.12/asyncio/tasks.py"},{"path":"/usr/lib/python3.12/asyncio/threads.py"},{"path":"/usr/lib/python3.12/asyncio/timeouts.py"},{"path":"/usr/lib/python3.12/asyncio/transports.py"},{"path":"/usr/lib/python3.12/asyncio/trsock.py"},{"path":"/usr/lib/python3.12/asyncio/unix_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_utils.py"},{"path":"/usr/lib/python3.12/collections"},{"path":"/usr/lib/python3.12/collections/__init__.py"},{"path":"/usr/lib/python3.12/collections/abc.py"},{"path":"/usr/lib/python3.12/concurrent"},{"path":"/usr/lib/python3.12/concurrent/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures"},{"path":"/usr/lib/python3.12/concurrent/futures/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures/_base.py"},{"path":"/usr/lib/python3.12/concurrent/futures/process.py"},{"path":"/usr/lib/python3.12/concurrent/futures/thread.py"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Makefile"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.bootstrap"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.local"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.stdlib"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/config.c.in"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/install-sh"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/makesetup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/python-config.py"},{"path":"/usr/lib/python3.12/ctypes"},{"path":"/usr/lib/python3.12/ctypes/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/_aix.py"},{"path":"/usr/lib/python3.12/ctypes/_endian.py"},{"path":"/usr/lib/python3.12/ctypes/util.py"},{"path":"/usr/lib/python3.12/ctypes/wintypes.py"},{"path":"/usr/lib/python3.12/ctypes/macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/README.ctypes"},{"path":"/usr/lib/python3.12/ctypes/macholib/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dyld.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dylib.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib.bat"},{"path":"/usr/lib/python3.12/ctypes/macholib/framework.py"},{"path":"/usr/lib/python3.12/curses"},{"path":"/usr/lib/python3.12/curses/__init__.py"},{"path":"/usr/lib/python3.12/curses/ascii.py"},{"path":"/usr/lib/python3.12/curses/has_key.py"},{"path":"/usr/lib/python3.12/curses/panel.py"},{"path":"/usr/lib/python3.12/curses/textpad.py"},{"path":"/usr/lib/python3.12/dbm"},{"path":"/usr/lib/python3.12/dbm/__init__.py"},{"path":"/usr/lib/python3.12/dbm/dumb.py"},{"path":"/usr/lib/python3.12/dbm/gnu.py"},{"path":"/usr/lib/python3.12/dbm/ndbm.py"},{"path":"/usr/lib/python3.12/email"},{"path":"/usr/lib/python3.12/email/__init__.py"},{"path":"/usr/lib/python3.12/email/_encoded_words.py"},{"path":"/usr/lib/python3.12/email/_header_value_parser.py"},{"path":"/usr/lib/python3.12/email/_parseaddr.py"},{"path":"/usr/lib/python3.12/email/_policybase.py"},{"path":"/usr/lib/python3.12/email/architecture.rst"},{"path":"/usr/lib/python3.12/email/base64mime.py"},{"path":"/usr/lib/python3.12/email/charset.py"},{"path":"/usr/lib/python3.12/email/contentmanager.py"},{"path":"/usr/lib/python3.12/email/encoders.py"},{"path":"/usr/lib/python3.12/email/errors.py"},{"path":"/usr/lib/python3.12/email/feedparser.py"},{"path":"/usr/lib/python3.12/email/generator.py"},{"path":"/usr/lib/python3.12/email/header.py"},{"path":"/usr/lib/python3.12/email/headerregistry.py"},{"path":"/usr/lib/python3.12/email/iterators.py"},{"path":"/usr/lib/python3.12/email/message.py"},{"path":"/usr/lib/python3.12/email/parser.py"},{"path":"/usr/lib/python3.12/email/policy.py"},{"path":"/usr/lib/python3.12/email/quoprimime.py"},{"path":"/usr/lib/python3.12/email/utils.py"},{"path":"/usr/lib/python3.12/email/mime"},{"path":"/usr/lib/python3.12/email/mime/__init__.py"},{"path":"/usr/lib/python3.12/email/mime/application.py"},{"path":"/usr/lib/python3.12/email/mime/audio.py"},{"path":"/usr/lib/python3.12/email/mime/base.py"},{"path":"/usr/lib/python3.12/email/mime/image.py"},{"path":"/usr/lib/python3.12/email/mime/message.py"},{"path":"/usr/lib/python3.12/email/mime/multipart.py"},{"path":"/usr/lib/python3.12/email/mime/nonmultipart.py"},{"path":"/usr/lib/python3.12/email/mime/text.py"},{"path":"/usr/lib/python3.12/encodings"},{"path":"/usr/lib/python3.12/encodings/__init__.py"},{"path":"/usr/lib/python3.12/encodings/aliases.py"},{"path":"/usr/lib/python3.12/encodings/ascii.py"},{"path":"/usr/lib/python3.12/encodings/base64_codec.py"},{"path":"/usr/lib/python3.12/encodings/big5.py"},{"path":"/usr/lib/python3.12/encodings/big5hkscs.py"},{"path":"/usr/lib/python3.12/encodings/bz2_codec.py"},{"path":"/usr/lib/python3.12/encodings/charmap.py"},{"path":"/usr/lib/python3.12/encodings/cp037.py"},{"path":"/usr/lib/python3.12/encodings/cp1006.py"},{"path":"/usr/lib/python3.12/encodings/cp1026.py"},{"path":"/usr/lib/python3.12/encodings/cp1125.py"},{"path":"/usr/lib/python3.12/encodings/cp1140.py"},{"path":"/usr/lib/python3.12/encodings/cp1250.py"},{"path":"/usr/lib/python3.12/encodings/cp1251.py"},{"path":"/usr/lib/python3.12/encodings/cp1252.py"},{"path":"/usr/lib/python3.12/encodings/cp1253.py"},{"path":"/usr/lib/python3.12/encodings/cp1254.py"},{"path":"/usr/lib/python3.12/encodings/cp1255.py"},{"path":"/usr/lib/python3.12/encodings/cp1256.py"},{"path":"/usr/lib/python3.12/encodings/cp1257.py"},{"path":"/usr/lib/python3.12/encodings/cp1258.py"},{"path":"/usr/lib/python3.12/encodings/cp273.py"},{"path":"/usr/lib/python3.12/encodings/cp424.py"},{"path":"/usr/lib/python3.12/encodings/cp437.py"},{"path":"/usr/lib/python3.12/encodings/cp500.py"},{"path":"/usr/lib/python3.12/encodings/cp720.py"},{"path":"/usr/lib/python3.12/encodings/cp737.py"},{"path":"/usr/lib/python3.12/encodings/cp775.py"},{"path":"/usr/lib/python3.12/encodings/cp850.py"},{"path":"/usr/lib/python3.12/encodings/cp852.py"},{"path":"/usr/lib/python3.12/encodings/cp855.py"},{"path":"/usr/lib/python3.12/encodings/cp856.py"},{"path":"/usr/lib/python3.12/encodings/cp857.py"},{"path":"/usr/lib/python3.12/encodings/cp858.py"},{"path":"/usr/lib/python3.12/encodings/cp860.py"},{"path":"/usr/lib/python3.12/encodings/cp861.py"},{"path":"/usr/lib/python3.12/encodings/cp862.py"},{"path":"/usr/lib/python3.12/encodings/cp863.py"},{"path":"/usr/lib/python3.12/encodings/cp864.py"},{"path":"/usr/lib/python3.12/encodings/cp865.py"},{"path":"/usr/lib/python3.12/encodings/cp866.py"},{"path":"/usr/lib/python3.12/encodings/cp869.py"},{"path":"/usr/lib/python3.12/encodings/cp874.py"},{"path":"/usr/lib/python3.12/encodings/cp875.py"},{"path":"/usr/lib/python3.12/encodings/cp932.py"},{"path":"/usr/lib/python3.12/encodings/cp949.py"},{"path":"/usr/lib/python3.12/encodings/cp950.py"},{"path":"/usr/lib/python3.12/encodings/euc_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/euc_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/euc_jp.py"},{"path":"/usr/lib/python3.12/encodings/euc_kr.py"},{"path":"/usr/lib/python3.12/encodings/gb18030.py"},{"path":"/usr/lib/python3.12/encodings/gb2312.py"},{"path":"/usr/lib/python3.12/encodings/gbk.py"},{"path":"/usr/lib/python3.12/encodings/hex_codec.py"},{"path":"/usr/lib/python3.12/encodings/hp_roman8.py"},{"path":"/usr/lib/python3.12/encodings/hz.py"},{"path":"/usr/lib/python3.12/encodings/idna.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_1.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2004.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_3.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_ext.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_kr.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_1.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_10.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_11.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_13.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_14.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_15.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_16.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_2.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_3.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_4.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_5.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_6.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_7.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_8.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_9.py"},{"path":"/usr/lib/python3.12/encodings/johab.py"},{"path":"/usr/lib/python3.12/encodings/koi8_r.py"},{"path":"/usr/lib/python3.12/encodings/koi8_t.py"},{"path":"/usr/lib/python3.12/encodings/koi8_u.py"},{"path":"/usr/lib/python3.12/encodings/kz1048.py"},{"path":"/usr/lib/python3.12/encodings/latin_1.py"},{"path":"/usr/lib/python3.12/encodings/mac_arabic.py"},{"path":"/usr/lib/python3.12/encodings/mac_croatian.py"},{"path":"/usr/lib/python3.12/encodings/mac_cyrillic.py"},{"path":"/usr/lib/python3.12/encodings/mac_farsi.py"},{"path":"/usr/lib/python3.12/encodings/mac_greek.py"},{"path":"/usr/lib/python3.12/encodings/mac_iceland.py"},{"path":"/usr/lib/python3.12/encodings/mac_latin2.py"},{"path":"/usr/lib/python3.12/encodings/mac_roman.py"},{"path":"/usr/lib/python3.12/encodings/mac_romanian.py"},{"path":"/usr/lib/python3.12/encodings/mac_turkish.py"},{"path":"/usr/lib/python3.12/encodings/mbcs.py"},{"path":"/usr/lib/python3.12/encodings/oem.py"},{"path":"/usr/lib/python3.12/encodings/palmos.py"},{"path":"/usr/lib/python3.12/encodings/ptcp154.py"},{"path":"/usr/lib/python3.12/encodings/punycode.py"},{"path":"/usr/lib/python3.12/encodings/quopri_codec.py"},{"path":"/usr/lib/python3.12/encodings/raw_unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/rot_13.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/shift_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/tis_620.py"},{"path":"/usr/lib/python3.12/encodings/undefined.py"},{"path":"/usr/lib/python3.12/encodings/unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/utf_16.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_32.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_7.py"},{"path":"/usr/lib/python3.12/encodings/utf_8.py"},{"path":"/usr/lib/python3.12/encodings/utf_8_sig.py"},{"path":"/usr/lib/python3.12/encodings/uu_codec.py"},{"path":"/usr/lib/python3.12/encodings/zlib_codec.py"},{"path":"/usr/lib/python3.12/ensurepip"},{"path":"/usr/lib/python3.12/ensurepip/__init__.py"},{"path":"/usr/lib/python3.12/ensurepip/__main__.py"},{"path":"/usr/lib/python3.12/ensurepip/_uninstall.py"},{"path":"/usr/lib/python3.12/ensurepip/_bundled"},{"path":"/usr/lib/python3.12/ensurepip/_bundled/pip-25.0.1-py3-none-any.whl"},{"path":"/usr/lib/python3.12/html"},{"path":"/usr/lib/python3.12/html/__init__.py"},{"path":"/usr/lib/python3.12/html/entities.py"},{"path":"/usr/lib/python3.12/html/parser.py"},{"path":"/usr/lib/python3.12/http"},{"path":"/usr/lib/python3.12/http/__init__.py"},{"path":"/usr/lib/python3.12/http/client.py"},{"path":"/usr/lib/python3.12/http/cookiejar.py"},{"path":"/usr/lib/python3.12/http/cookies.py"},{"path":"/usr/lib/python3.12/http/server.py"},{"path":"/usr/lib/python3.12/importlib"},{"path":"/usr/lib/python3.12/importlib/__init__.py"},{"path":"/usr/lib/python3.12/importlib/_abc.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap_external.py"},{"path":"/usr/lib/python3.12/importlib/abc.py"},{"path":"/usr/lib/python3.12/importlib/machinery.py"},{"path":"/usr/lib/python3.12/importlib/readers.py"},{"path":"/usr/lib/python3.12/importlib/simple.py"},{"path":"/usr/lib/python3.12/importlib/util.py"},{"path":"/usr/lib/python3.12/importlib/metadata"},{"path":"/usr/lib/python3.12/importlib/metadata/__init__.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_collections.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_functools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_meta.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_text.py"},{"path":"/usr/lib/python3.12/importlib/resources"},{"path":"/usr/lib/python3.12/importlib/resources/__init__.py"},{"path":"/usr/lib/python3.12/importlib/resources/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/resources/_common.py"},{"path":"/usr/lib/python3.12/importlib/resources/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/resources/_legacy.py"},{"path":"/usr/lib/python3.12/importlib/resources/abc.py"},{"path":"/usr/lib/python3.12/importlib/resources/readers.py"},{"path":"/usr/lib/python3.12/importlib/resources/simple.py"},{"path":"/usr/lib/python3.12/json"},{"path":"/usr/lib/python3.12/json/__init__.py"},{"path":"/usr/lib/python3.12/json/decoder.py"},{"path":"/usr/lib/python3.12/json/encoder.py"},{"path":"/usr/lib/python3.12/json/scanner.py"},{"path":"/usr/lib/python3.12/json/tool.py"},{"path":"/usr/lib/python3.12/lib-dynload"},{"path":"/usr/lib/python3.12/lib-dynload/_asyncio.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bisect.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_blake2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bz2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_cn.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_hk.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_iso2022.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_jp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_kr.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_tw.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_contextvars.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_crypt.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_csv.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes_test.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses_panel.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_datetime.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_dbm.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_decimal.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_elementtree.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_hashlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_heapq.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_json.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lsprof.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lzma.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_md5.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multibytecodec.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multiprocessing.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_opcode.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_pickle.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixshmem.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixsubprocess.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_queue.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_random.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha1.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_socket.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sqlite3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ssl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_statistics.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_struct.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testbuffer.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testclinic.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testimportmultiple.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testinternalcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testmultiphase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testsinglephase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxinterpchannels.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxsubinterpreters.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxtestfuzz.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_zoneinfo.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/array.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/audioop.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/binascii.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/cmath.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/fcntl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/grp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/math.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/mmap.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/ossaudiodev.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/pyexpat.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/readline.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/resource.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/select.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/spwd.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/syslog.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/termios.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/unicodedata.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited_35.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxsubtype.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/zlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib2to3"},{"path":"/usr/lib/python3.12/lib2to3/Grammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/Grammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/__main__.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_matcher.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_utils.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_base.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_util.py"},{"path":"/usr/lib/python3.12/lib2to3/main.py"},{"path":"/usr/lib/python3.12/lib2to3/patcomp.py"},{"path":"/usr/lib/python3.12/lib2to3/pygram.py"},{"path":"/usr/lib/python3.12/lib2to3/pytree.py"},{"path":"/usr/lib/python3.12/lib2to3/refactor.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes"},{"path":"/usr/lib/python3.12/lib2to3/fixes/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_apply.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_asserts.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_basestring.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_buffer.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_dict.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_except.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exec.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_execfile.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exitfunc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_filter.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_funcattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_future.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_getcwdu.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_has_key.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_idioms.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_import.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports2.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_intern.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_isinstance.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_long.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_map.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_metaclass.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_methodattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ne.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_next.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_nonzero.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_numliterals.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_operator.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_paren.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_print.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raise.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raw_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reduce.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reload.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_renames.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_repr.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_set_literal.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_standarderror.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_sys_exc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_throw.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_tuple_params.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_types.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_unicode.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_urllib.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ws_comma.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xrange.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xreadlines.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_zip.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/conv.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/driver.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/grammar.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/literals.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/parse.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/pgen.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/token.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/tokenize.py"},{"path":"/usr/lib/python3.12/logging"},{"path":"/usr/lib/python3.12/logging/__init__.py"},{"path":"/usr/lib/python3.12/logging/config.py"},{"path":"/usr/lib/python3.12/logging/handlers.py"},{"path":"/usr/lib/python3.12/multiprocessing"},{"path":"/usr/lib/python3.12/multiprocessing/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/connection.py"},{"path":"/usr/lib/python3.12/multiprocessing/context.py"},{"path":"/usr/lib/python3.12/multiprocessing/forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/heap.py"},{"path":"/usr/lib/python3.12/multiprocessing/managers.py"},{"path":"/usr/lib/python3.12/multiprocessing/pool.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_fork.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_posix.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_win32.py"},{"path":"/usr/lib/python3.12/multiprocessing/process.py"},{"path":"/usr/lib/python3.12/multiprocessing/queues.py"},{"path":"/usr/lib/python3.12/multiprocessing/reduction.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_sharer.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_tracker.py"},{"path":"/usr/lib/python3.12/multiprocessing/shared_memory.py"},{"path":"/usr/lib/python3.12/multiprocessing/sharedctypes.py"},{"path":"/usr/lib/python3.12/multiprocessing/spawn.py"},{"path":"/usr/lib/python3.12/multiprocessing/synchronize.py"},{"path":"/usr/lib/python3.12/multiprocessing/util.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/connection.py"},{"path":"/usr/lib/python3.12/pydoc_data"},{"path":"/usr/lib/python3.12/pydoc_data/__init__.py"},{"path":"/usr/lib/python3.12/pydoc_data/_pydoc.css"},{"path":"/usr/lib/python3.12/pydoc_data/topics.py"},{"path":"/usr/lib/python3.12/re"},{"path":"/usr/lib/python3.12/re/__init__.py"},{"path":"/usr/lib/python3.12/re/_casefix.py"},{"path":"/usr/lib/python3.12/re/_compiler.py"},{"path":"/usr/lib/python3.12/re/_constants.py"},{"path":"/usr/lib/python3.12/re/_parser.py"},{"path":"/usr/lib/python3.12/site-packages"},{"path":"/usr/lib/python3.12/site-packages/README.txt"},{"path":"/usr/lib/python3.12/sqlite3"},{"path":"/usr/lib/python3.12/sqlite3/__init__.py"},{"path":"/usr/lib/python3.12/sqlite3/__main__.py"},{"path":"/usr/lib/python3.12/sqlite3/dbapi2.py"},{"path":"/usr/lib/python3.12/sqlite3/dump.py"},{"path":"/usr/lib/python3.12/tomllib"},{"path":"/usr/lib/python3.12/tomllib/__init__.py"},{"path":"/usr/lib/python3.12/tomllib/_parser.py"},{"path":"/usr/lib/python3.12/tomllib/_re.py"},{"path":"/usr/lib/python3.12/tomllib/_types.py"},{"path":"/usr/lib/python3.12/turtledemo"},{"path":"/usr/lib/python3.12/turtledemo/__init__.py"},{"path":"/usr/lib/python3.12/turtledemo/__main__.py"},{"path":"/usr/lib/python3.12/turtledemo/bytedesign.py"},{"path":"/usr/lib/python3.12/turtledemo/chaos.py"},{"path":"/usr/lib/python3.12/turtledemo/clock.py"},{"path":"/usr/lib/python3.12/turtledemo/colormixer.py"},{"path":"/usr/lib/python3.12/turtledemo/forest.py"},{"path":"/usr/lib/python3.12/turtledemo/fractalcurves.py"},{"path":"/usr/lib/python3.12/turtledemo/lindenmayer.py"},{"path":"/usr/lib/python3.12/turtledemo/minimal_hanoi.py"},{"path":"/usr/lib/python3.12/turtledemo/nim.py"},{"path":"/usr/lib/python3.12/turtledemo/paint.py"},{"path":"/usr/lib/python3.12/turtledemo/peace.py"},{"path":"/usr/lib/python3.12/turtledemo/penrose.py"},{"path":"/usr/lib/python3.12/turtledemo/planet_and_moon.py"},{"path":"/usr/lib/python3.12/turtledemo/rosette.py"},{"path":"/usr/lib/python3.12/turtledemo/round_dance.py"},{"path":"/usr/lib/python3.12/turtledemo/sorting_animate.py"},{"path":"/usr/lib/python3.12/turtledemo/tree.py"},{"path":"/usr/lib/python3.12/turtledemo/turtle.cfg"},{"path":"/usr/lib/python3.12/turtledemo/two_canvases.py"},{"path":"/usr/lib/python3.12/turtledemo/yinyang.py"},{"path":"/usr/lib/python3.12/unittest"},{"path":"/usr/lib/python3.12/unittest/__init__.py"},{"path":"/usr/lib/python3.12/unittest/__main__.py"},{"path":"/usr/lib/python3.12/unittest/_log.py"},{"path":"/usr/lib/python3.12/unittest/async_case.py"},{"path":"/usr/lib/python3.12/unittest/case.py"},{"path":"/usr/lib/python3.12/unittest/loader.py"},{"path":"/usr/lib/python3.12/unittest/main.py"},{"path":"/usr/lib/python3.12/unittest/mock.py"},{"path":"/usr/lib/python3.12/unittest/result.py"},{"path":"/usr/lib/python3.12/unittest/runner.py"},{"path":"/usr/lib/python3.12/unittest/signals.py"},{"path":"/usr/lib/python3.12/unittest/suite.py"},{"path":"/usr/lib/python3.12/unittest/util.py"},{"path":"/usr/lib/python3.12/urllib"},{"path":"/usr/lib/python3.12/urllib/__init__.py"},{"path":"/usr/lib/python3.12/urllib/error.py"},{"path":"/usr/lib/python3.12/urllib/parse.py"},{"path":"/usr/lib/python3.12/urllib/request.py"},{"path":"/usr/lib/python3.12/urllib/response.py"},{"path":"/usr/lib/python3.12/urllib/robotparser.py"},{"path":"/usr/lib/python3.12/venv"},{"path":"/usr/lib/python3.12/venv/__init__.py"},{"path":"/usr/lib/python3.12/venv/__main__.py"},{"path":"/usr/lib/python3.12/venv/scripts"},{"path":"/usr/lib/python3.12/venv/scripts/common"},{"path":"/usr/lib/python3.12/venv/scripts/common/Activate.ps1"},{"path":"/usr/lib/python3.12/venv/scripts/common/activate"},{"path":"/usr/lib/python3.12/venv/scripts/posix"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.csh"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.fish"},{"path":"/usr/lib/python3.12/wsgiref"},{"path":"/usr/lib/python3.12/wsgiref/__init__.py"},{"path":"/usr/lib/python3.12/wsgiref/handlers.py"},{"path":"/usr/lib/python3.12/wsgiref/headers.py"},{"path":"/usr/lib/python3.12/wsgiref/simple_server.py"},{"path":"/usr/lib/python3.12/wsgiref/types.py"},{"path":"/usr/lib/python3.12/wsgiref/util.py"},{"path":"/usr/lib/python3.12/wsgiref/validate.py"},{"path":"/usr/lib/python3.12/xml"},{"path":"/usr/lib/python3.12/xml/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom"},{"path":"/usr/lib/python3.12/xml/dom/NodeFilter.py"},{"path":"/usr/lib/python3.12/xml/dom/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom/domreg.py"},{"path":"/usr/lib/python3.12/xml/dom/expatbuilder.py"},{"path":"/usr/lib/python3.12/xml/dom/minicompat.py"},{"path":"/usr/lib/python3.12/xml/dom/minidom.py"},{"path":"/usr/lib/python3.12/xml/dom/pulldom.py"},{"path":"/usr/lib/python3.12/xml/dom/xmlbuilder.py"},{"path":"/usr/lib/python3.12/xml/etree"},{"path":"/usr/lib/python3.12/xml/etree/ElementInclude.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementPath.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementTree.py"},{"path":"/usr/lib/python3.12/xml/etree/__init__.py"},{"path":"/usr/lib/python3.12/xml/etree/cElementTree.py"},{"path":"/usr/lib/python3.12/xml/parsers"},{"path":"/usr/lib/python3.12/xml/parsers/__init__.py"},{"path":"/usr/lib/python3.12/xml/parsers/expat.py"},{"path":"/usr/lib/python3.12/xml/sax"},{"path":"/usr/lib/python3.12/xml/sax/__init__.py"},{"path":"/usr/lib/python3.12/xml/sax/_exceptions.py"},{"path":"/usr/lib/python3.12/xml/sax/expatreader.py"},{"path":"/usr/lib/python3.12/xml/sax/handler.py"},{"path":"/usr/lib/python3.12/xml/sax/saxutils.py"},{"path":"/usr/lib/python3.12/xml/sax/xmlreader.py"},{"path":"/usr/lib/python3.12/xmlrpc"},{"path":"/usr/lib/python3.12/xmlrpc/__init__.py"},{"path":"/usr/lib/python3.12/xmlrpc/client.py"},{"path":"/usr/lib/python3.12/xmlrpc/server.py"},{"path":"/usr/lib/python3.12/zipfile"},{"path":"/usr/lib/python3.12/zipfile/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/__main__.py"},{"path":"/usr/lib/python3.12/zipfile/_path"},{"path":"/usr/lib/python3.12/zipfile/_path/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/_path/glob.py"},{"path":"/usr/lib/python3.12/zoneinfo"},{"path":"/usr/lib/python3.12/zoneinfo/__init__.py"},{"path":"/usr/lib/python3.12/zoneinfo/_common.py"},{"path":"/usr/lib/python3.12/zoneinfo/_tzpath.py"},{"path":"/usr/lib/python3.12/zoneinfo/_zoneinfo.py"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12781","versionConstraint":"< 3.13.10||>= 3.14.0, < 3.14.1||>= 3.15.0a1, < 3.15.0a2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}},{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12781","versionConstraint":"< 3.13.10||>= 3.14.0, < 3.14.1||>= 3.15.0a1, < 3.15.0a2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.30726,"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59849","versionConstraint":">= 0.11.0, < 0.11.5||= 0.12.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59849","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59849","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59849","date":"2026-10-08","epss":0.00438,"percentile":0.36062}],"risk":0.28032,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/security/cve/CVE-2026-59849","https://bugzilla.redhat.com/show_bug.cgi?id=2498182"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59849","description":"A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"09c24a4342b1cfdb","cpes":["cpe:2.3:a:python-software-foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.12.15-r0:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:apk/alpine/python3@3.12.15-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"3.12.15-r0","language":"","licenses":["PSF-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/2to3"},{"path":"/usr/bin/2to3-3.12"},{"path":"/usr/bin/pydoc3"},{"path":"/usr/bin/pydoc3.12"},{"path":"/usr/bin/python"},{"path":"/usr/bin/python3"},{"path":"/usr/bin/python3.12"},{"path":"/usr/include"},{"path":"/usr/include/python3.12"},{"path":"/usr/include/python3.12/pyconfig.h"},{"path":"/usr/lib"},{"path":"/usr/lib/libpython3.12.so.1.0"},{"path":"/usr/lib/libpython3.so"},{"path":"/usr/lib/python3.12"},{"path":"/usr/lib/python3.12/EXTERNALLY-MANAGED"},{"path":"/usr/lib/python3.12/LICENSE.txt"},{"path":"/usr/lib/python3.12/__future__.py"},{"path":"/usr/lib/python3.12/__hello__.py"},{"path":"/usr/lib/python3.12/_aix_support.py"},{"path":"/usr/lib/python3.12/_collections_abc.py"},{"path":"/usr/lib/python3.12/_compat_pickle.py"},{"path":"/usr/lib/python3.12/_compression.py"},{"path":"/usr/lib/python3.12/_markupbase.py"},{"path":"/usr/lib/python3.12/_osx_support.py"},{"path":"/usr/lib/python3.12/_py_abc.py"},{"path":"/usr/lib/python3.12/_pydatetime.py"},{"path":"/usr/lib/python3.12/_pydecimal.py"},{"path":"/usr/lib/python3.12/_pyio.py"},{"path":"/usr/lib/python3.12/_pylong.py"},{"path":"/usr/lib/python3.12/_sitebuiltins.py"},{"path":"/usr/lib/python3.12/_strptime.py"},{"path":"/usr/lib/python3.12/_sysconfigdata__linux_x86_64-linux-musl.py"},{"path":"/usr/lib/python3.12/_threading_local.py"},{"path":"/usr/lib/python3.12/_weakrefset.py"},{"path":"/usr/lib/python3.12/abc.py"},{"path":"/usr/lib/python3.12/aifc.py"},{"path":"/usr/lib/python3.12/antigravity.py"},{"path":"/usr/lib/python3.12/argparse.py"},{"path":"/usr/lib/python3.12/ast.py"},{"path":"/usr/lib/python3.12/base64.py"},{"path":"/usr/lib/python3.12/bdb.py"},{"path":"/usr/lib/python3.12/bisect.py"},{"path":"/usr/lib/python3.12/bz2.py"},{"path":"/usr/lib/python3.12/cProfile.py"},{"path":"/usr/lib/python3.12/calendar.py"},{"path":"/usr/lib/python3.12/cgi.py"},{"path":"/usr/lib/python3.12/cgitb.py"},{"path":"/usr/lib/python3.12/chunk.py"},{"path":"/usr/lib/python3.12/cmd.py"},{"path":"/usr/lib/python3.12/code.py"},{"path":"/usr/lib/python3.12/codecs.py"},{"path":"/usr/lib/python3.12/codeop.py"},{"path":"/usr/lib/python3.12/colorsys.py"},{"path":"/usr/lib/python3.12/compileall.py"},{"path":"/usr/lib/python3.12/configparser.py"},{"path":"/usr/lib/python3.12/contextlib.py"},{"path":"/usr/lib/python3.12/contextvars.py"},{"path":"/usr/lib/python3.12/copy.py"},{"path":"/usr/lib/python3.12/copyreg.py"},{"path":"/usr/lib/python3.12/crypt.py"},{"path":"/usr/lib/python3.12/csv.py"},{"path":"/usr/lib/python3.12/dataclasses.py"},{"path":"/usr/lib/python3.12/datetime.py"},{"path":"/usr/lib/python3.12/decimal.py"},{"path":"/usr/lib/python3.12/difflib.py"},{"path":"/usr/lib/python3.12/dis.py"},{"path":"/usr/lib/python3.12/doctest.py"},{"path":"/usr/lib/python3.12/enum.py"},{"path":"/usr/lib/python3.12/filecmp.py"},{"path":"/usr/lib/python3.12/fileinput.py"},{"path":"/usr/lib/python3.12/fnmatch.py"},{"path":"/usr/lib/python3.12/fractions.py"},{"path":"/usr/lib/python3.12/ftplib.py"},{"path":"/usr/lib/python3.12/functools.py"},{"path":"/usr/lib/python3.12/genericpath.py"},{"path":"/usr/lib/python3.12/getopt.py"},{"path":"/usr/lib/python3.12/getpass.py"},{"path":"/usr/lib/python3.12/gettext.py"},{"path":"/usr/lib/python3.12/glob.py"},{"path":"/usr/lib/python3.12/graphlib.py"},{"path":"/usr/lib/python3.12/gzip.py"},{"path":"/usr/lib/python3.12/hashlib.py"},{"path":"/usr/lib/python3.12/heapq.py"},{"path":"/usr/lib/python3.12/hmac.py"},{"path":"/usr/lib/python3.12/imaplib.py"},{"path":"/usr/lib/python3.12/imghdr.py"},{"path":"/usr/lib/python3.12/inspect.py"},{"path":"/usr/lib/python3.12/io.py"},{"path":"/usr/lib/python3.12/ipaddress.py"},{"path":"/usr/lib/python3.12/keyword.py"},{"path":"/usr/lib/python3.12/linecache.py"},{"path":"/usr/lib/python3.12/locale.py"},{"path":"/usr/lib/python3.12/lzma.py"},{"path":"/usr/lib/python3.12/mailbox.py"},{"path":"/usr/lib/python3.12/mailcap.py"},{"path":"/usr/lib/python3.12/mimetypes.py"},{"path":"/usr/lib/python3.12/modulefinder.py"},{"path":"/usr/lib/python3.12/netrc.py"},{"path":"/usr/lib/python3.12/nntplib.py"},{"path":"/usr/lib/python3.12/ntpath.py"},{"path":"/usr/lib/python3.12/nturl2path.py"},{"path":"/usr/lib/python3.12/numbers.py"},{"path":"/usr/lib/python3.12/opcode.py"},{"path":"/usr/lib/python3.12/operator.py"},{"path":"/usr/lib/python3.12/optparse.py"},{"path":"/usr/lib/python3.12/os.py"},{"path":"/usr/lib/python3.12/pathlib.py"},{"path":"/usr/lib/python3.12/pdb.py"},{"path":"/usr/lib/python3.12/pickle.py"},{"path":"/usr/lib/python3.12/pickletools.py"},{"path":"/usr/lib/python3.12/pipes.py"},{"path":"/usr/lib/python3.12/pkgutil.py"},{"path":"/usr/lib/python3.12/platform.py"},{"path":"/usr/lib/python3.12/plistlib.py"},{"path":"/usr/lib/python3.12/poplib.py"},{"path":"/usr/lib/python3.12/posixpath.py"},{"path":"/usr/lib/python3.12/pprint.py"},{"path":"/usr/lib/python3.12/profile.py"},{"path":"/usr/lib/python3.12/pstats.py"},{"path":"/usr/lib/python3.12/pty.py"},{"path":"/usr/lib/python3.12/py_compile.py"},{"path":"/usr/lib/python3.12/pyclbr.py"},{"path":"/usr/lib/python3.12/pydoc.py"},{"path":"/usr/lib/python3.12/queue.py"},{"path":"/usr/lib/python3.12/quopri.py"},{"path":"/usr/lib/python3.12/random.py"},{"path":"/usr/lib/python3.12/reprlib.py"},{"path":"/usr/lib/python3.12/rlcompleter.py"},{"path":"/usr/lib/python3.12/runpy.py"},{"path":"/usr/lib/python3.12/sched.py"},{"path":"/usr/lib/python3.12/secrets.py"},{"path":"/usr/lib/python3.12/selectors.py"},{"path":"/usr/lib/python3.12/shelve.py"},{"path":"/usr/lib/python3.12/shlex.py"},{"path":"/usr/lib/python3.12/shutil.py"},{"path":"/usr/lib/python3.12/signal.py"},{"path":"/usr/lib/python3.12/site.py"},{"path":"/usr/lib/python3.12/smtplib.py"},{"path":"/usr/lib/python3.12/sndhdr.py"},{"path":"/usr/lib/python3.12/socket.py"},{"path":"/usr/lib/python3.12/socketserver.py"},{"path":"/usr/lib/python3.12/sre_compile.py"},{"path":"/usr/lib/python3.12/sre_constants.py"},{"path":"/usr/lib/python3.12/sre_parse.py"},{"path":"/usr/lib/python3.12/ssl.py"},{"path":"/usr/lib/python3.12/stat.py"},{"path":"/usr/lib/python3.12/statistics.py"},{"path":"/usr/lib/python3.12/string.py"},{"path":"/usr/lib/python3.12/stringprep.py"},{"path":"/usr/lib/python3.12/struct.py"},{"path":"/usr/lib/python3.12/subprocess.py"},{"path":"/usr/lib/python3.12/sunau.py"},{"path":"/usr/lib/python3.12/symtable.py"},{"path":"/usr/lib/python3.12/sysconfig.py"},{"path":"/usr/lib/python3.12/tabnanny.py"},{"path":"/usr/lib/python3.12/tarfile.py"},{"path":"/usr/lib/python3.12/telnetlib.py"},{"path":"/usr/lib/python3.12/tempfile.py"},{"path":"/usr/lib/python3.12/textwrap.py"},{"path":"/usr/lib/python3.12/this.py"},{"path":"/usr/lib/python3.12/threading.py"},{"path":"/usr/lib/python3.12/timeit.py"},{"path":"/usr/lib/python3.12/token.py"},{"path":"/usr/lib/python3.12/tokenize.py"},{"path":"/usr/lib/python3.12/trace.py"},{"path":"/usr/lib/python3.12/traceback.py"},{"path":"/usr/lib/python3.12/tracemalloc.py"},{"path":"/usr/lib/python3.12/tty.py"},{"path":"/usr/lib/python3.12/turtle.py"},{"path":"/usr/lib/python3.12/types.py"},{"path":"/usr/lib/python3.12/typing.py"},{"path":"/usr/lib/python3.12/uu.py"},{"path":"/usr/lib/python3.12/uuid.py"},{"path":"/usr/lib/python3.12/warnings.py"},{"path":"/usr/lib/python3.12/wave.py"},{"path":"/usr/lib/python3.12/weakref.py"},{"path":"/usr/lib/python3.12/webbrowser.py"},{"path":"/usr/lib/python3.12/xdrlib.py"},{"path":"/usr/lib/python3.12/zipapp.py"},{"path":"/usr/lib/python3.12/zipimport.py"},{"path":"/usr/lib/python3.12/__phello__"},{"path":"/usr/lib/python3.12/__phello__/__init__.py"},{"path":"/usr/lib/python3.12/__phello__/spam.py"},{"path":"/usr/lib/python3.12/asyncio"},{"path":"/usr/lib/python3.12/asyncio/__init__.py"},{"path":"/usr/lib/python3.12/asyncio/__main__.py"},{"path":"/usr/lib/python3.12/asyncio/base_events.py"},{"path":"/usr/lib/python3.12/asyncio/base_futures.py"},{"path":"/usr/lib/python3.12/asyncio/base_subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/base_tasks.py"},{"path":"/usr/lib/python3.12/asyncio/constants.py"},{"path":"/usr/lib/python3.12/asyncio/coroutines.py"},{"path":"/usr/lib/python3.12/asyncio/events.py"},{"path":"/usr/lib/python3.12/asyncio/exceptions.py"},{"path":"/usr/lib/python3.12/asyncio/format_helpers.py"},{"path":"/usr/lib/python3.12/asyncio/futures.py"},{"path":"/usr/lib/python3.12/asyncio/locks.py"},{"path":"/usr/lib/python3.12/asyncio/log.py"},{"path":"/usr/lib/python3.12/asyncio/mixins.py"},{"path":"/usr/lib/python3.12/asyncio/proactor_events.py"},{"path":"/usr/lib/python3.12/asyncio/protocols.py"},{"path":"/usr/lib/python3.12/asyncio/queues.py"},{"path":"/usr/lib/python3.12/asyncio/runners.py"},{"path":"/usr/lib/python3.12/asyncio/selector_events.py"},{"path":"/usr/lib/python3.12/asyncio/sslproto.py"},{"path":"/usr/lib/python3.12/asyncio/staggered.py"},{"path":"/usr/lib/python3.12/asyncio/streams.py"},{"path":"/usr/lib/python3.12/asyncio/subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/taskgroups.py"},{"path":"/usr/lib/python3.12/asyncio/tasks.py"},{"path":"/usr/lib/python3.12/asyncio/threads.py"},{"path":"/usr/lib/python3.12/asyncio/timeouts.py"},{"path":"/usr/lib/python3.12/asyncio/transports.py"},{"path":"/usr/lib/python3.12/asyncio/trsock.py"},{"path":"/usr/lib/python3.12/asyncio/unix_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_utils.py"},{"path":"/usr/lib/python3.12/collections"},{"path":"/usr/lib/python3.12/collections/__init__.py"},{"path":"/usr/lib/python3.12/collections/abc.py"},{"path":"/usr/lib/python3.12/concurrent"},{"path":"/usr/lib/python3.12/concurrent/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures"},{"path":"/usr/lib/python3.12/concurrent/futures/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures/_base.py"},{"path":"/usr/lib/python3.12/concurrent/futures/process.py"},{"path":"/usr/lib/python3.12/concurrent/futures/thread.py"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Makefile"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.bootstrap"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.local"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.stdlib"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/config.c.in"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/install-sh"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/makesetup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/python-config.py"},{"path":"/usr/lib/python3.12/ctypes"},{"path":"/usr/lib/python3.12/ctypes/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/_aix.py"},{"path":"/usr/lib/python3.12/ctypes/_endian.py"},{"path":"/usr/lib/python3.12/ctypes/util.py"},{"path":"/usr/lib/python3.12/ctypes/wintypes.py"},{"path":"/usr/lib/python3.12/ctypes/macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/README.ctypes"},{"path":"/usr/lib/python3.12/ctypes/macholib/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dyld.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dylib.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib.bat"},{"path":"/usr/lib/python3.12/ctypes/macholib/framework.py"},{"path":"/usr/lib/python3.12/curses"},{"path":"/usr/lib/python3.12/curses/__init__.py"},{"path":"/usr/lib/python3.12/curses/ascii.py"},{"path":"/usr/lib/python3.12/curses/has_key.py"},{"path":"/usr/lib/python3.12/curses/panel.py"},{"path":"/usr/lib/python3.12/curses/textpad.py"},{"path":"/usr/lib/python3.12/dbm"},{"path":"/usr/lib/python3.12/dbm/__init__.py"},{"path":"/usr/lib/python3.12/dbm/dumb.py"},{"path":"/usr/lib/python3.12/dbm/gnu.py"},{"path":"/usr/lib/python3.12/dbm/ndbm.py"},{"path":"/usr/lib/python3.12/email"},{"path":"/usr/lib/python3.12/email/__init__.py"},{"path":"/usr/lib/python3.12/email/_encoded_words.py"},{"path":"/usr/lib/python3.12/email/_header_value_parser.py"},{"path":"/usr/lib/python3.12/email/_parseaddr.py"},{"path":"/usr/lib/python3.12/email/_policybase.py"},{"path":"/usr/lib/python3.12/email/architecture.rst"},{"path":"/usr/lib/python3.12/email/base64mime.py"},{"path":"/usr/lib/python3.12/email/charset.py"},{"path":"/usr/lib/python3.12/email/contentmanager.py"},{"path":"/usr/lib/python3.12/email/encoders.py"},{"path":"/usr/lib/python3.12/email/errors.py"},{"path":"/usr/lib/python3.12/email/feedparser.py"},{"path":"/usr/lib/python3.12/email/generator.py"},{"path":"/usr/lib/python3.12/email/header.py"},{"path":"/usr/lib/python3.12/email/headerregistry.py"},{"path":"/usr/lib/python3.12/email/iterators.py"},{"path":"/usr/lib/python3.12/email/message.py"},{"path":"/usr/lib/python3.12/email/parser.py"},{"path":"/usr/lib/python3.12/email/policy.py"},{"path":"/usr/lib/python3.12/email/quoprimime.py"},{"path":"/usr/lib/python3.12/email/utils.py"},{"path":"/usr/lib/python3.12/email/mime"},{"path":"/usr/lib/python3.12/email/mime/__init__.py"},{"path":"/usr/lib/python3.12/email/mime/application.py"},{"path":"/usr/lib/python3.12/email/mime/audio.py"},{"path":"/usr/lib/python3.12/email/mime/base.py"},{"path":"/usr/lib/python3.12/email/mime/image.py"},{"path":"/usr/lib/python3.12/email/mime/message.py"},{"path":"/usr/lib/python3.12/email/mime/multipart.py"},{"path":"/usr/lib/python3.12/email/mime/nonmultipart.py"},{"path":"/usr/lib/python3.12/email/mime/text.py"},{"path":"/usr/lib/python3.12/encodings"},{"path":"/usr/lib/python3.12/encodings/__init__.py"},{"path":"/usr/lib/python3.12/encodings/aliases.py"},{"path":"/usr/lib/python3.12/encodings/ascii.py"},{"path":"/usr/lib/python3.12/encodings/base64_codec.py"},{"path":"/usr/lib/python3.12/encodings/big5.py"},{"path":"/usr/lib/python3.12/encodings/big5hkscs.py"},{"path":"/usr/lib/python3.12/encodings/bz2_codec.py"},{"path":"/usr/lib/python3.12/encodings/charmap.py"},{"path":"/usr/lib/python3.12/encodings/cp037.py"},{"path":"/usr/lib/python3.12/encodings/cp1006.py"},{"path":"/usr/lib/python3.12/encodings/cp1026.py"},{"path":"/usr/lib/python3.12/encodings/cp1125.py"},{"path":"/usr/lib/python3.12/encodings/cp1140.py"},{"path":"/usr/lib/python3.12/encodings/cp1250.py"},{"path":"/usr/lib/python3.12/encodings/cp1251.py"},{"path":"/usr/lib/python3.12/encodings/cp1252.py"},{"path":"/usr/lib/python3.12/encodings/cp1253.py"},{"path":"/usr/lib/python3.12/encodings/cp1254.py"},{"path":"/usr/lib/python3.12/encodings/cp1255.py"},{"path":"/usr/lib/python3.12/encodings/cp1256.py"},{"path":"/usr/lib/python3.12/encodings/cp1257.py"},{"path":"/usr/lib/python3.12/encodings/cp1258.py"},{"path":"/usr/lib/python3.12/encodings/cp273.py"},{"path":"/usr/lib/python3.12/encodings/cp424.py"},{"path":"/usr/lib/python3.12/encodings/cp437.py"},{"path":"/usr/lib/python3.12/encodings/cp500.py"},{"path":"/usr/lib/python3.12/encodings/cp720.py"},{"path":"/usr/lib/python3.12/encodings/cp737.py"},{"path":"/usr/lib/python3.12/encodings/cp775.py"},{"path":"/usr/lib/python3.12/encodings/cp850.py"},{"path":"/usr/lib/python3.12/encodings/cp852.py"},{"path":"/usr/lib/python3.12/encodings/cp855.py"},{"path":"/usr/lib/python3.12/encodings/cp856.py"},{"path":"/usr/lib/python3.12/encodings/cp857.py"},{"path":"/usr/lib/python3.12/encodings/cp858.py"},{"path":"/usr/lib/python3.12/encodings/cp860.py"},{"path":"/usr/lib/python3.12/encodings/cp861.py"},{"path":"/usr/lib/python3.12/encodings/cp862.py"},{"path":"/usr/lib/python3.12/encodings/cp863.py"},{"path":"/usr/lib/python3.12/encodings/cp864.py"},{"path":"/usr/lib/python3.12/encodings/cp865.py"},{"path":"/usr/lib/python3.12/encodings/cp866.py"},{"path":"/usr/lib/python3.12/encodings/cp869.py"},{"path":"/usr/lib/python3.12/encodings/cp874.py"},{"path":"/usr/lib/python3.12/encodings/cp875.py"},{"path":"/usr/lib/python3.12/encodings/cp932.py"},{"path":"/usr/lib/python3.12/encodings/cp949.py"},{"path":"/usr/lib/python3.12/encodings/cp950.py"},{"path":"/usr/lib/python3.12/encodings/euc_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/euc_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/euc_jp.py"},{"path":"/usr/lib/python3.12/encodings/euc_kr.py"},{"path":"/usr/lib/python3.12/encodings/gb18030.py"},{"path":"/usr/lib/python3.12/encodings/gb2312.py"},{"path":"/usr/lib/python3.12/encodings/gbk.py"},{"path":"/usr/lib/python3.12/encodings/hex_codec.py"},{"path":"/usr/lib/python3.12/encodings/hp_roman8.py"},{"path":"/usr/lib/python3.12/encodings/hz.py"},{"path":"/usr/lib/python3.12/encodings/idna.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_1.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2004.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_3.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_ext.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_kr.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_1.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_10.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_11.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_13.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_14.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_15.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_16.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_2.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_3.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_4.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_5.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_6.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_7.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_8.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_9.py"},{"path":"/usr/lib/python3.12/encodings/johab.py"},{"path":"/usr/lib/python3.12/encodings/koi8_r.py"},{"path":"/usr/lib/python3.12/encodings/koi8_t.py"},{"path":"/usr/lib/python3.12/encodings/koi8_u.py"},{"path":"/usr/lib/python3.12/encodings/kz1048.py"},{"path":"/usr/lib/python3.12/encodings/latin_1.py"},{"path":"/usr/lib/python3.12/encodings/mac_arabic.py"},{"path":"/usr/lib/python3.12/encodings/mac_croatian.py"},{"path":"/usr/lib/python3.12/encodings/mac_cyrillic.py"},{"path":"/usr/lib/python3.12/encodings/mac_farsi.py"},{"path":"/usr/lib/python3.12/encodings/mac_greek.py"},{"path":"/usr/lib/python3.12/encodings/mac_iceland.py"},{"path":"/usr/lib/python3.12/encodings/mac_latin2.py"},{"path":"/usr/lib/python3.12/encodings/mac_roman.py"},{"path":"/usr/lib/python3.12/encodings/mac_romanian.py"},{"path":"/usr/lib/python3.12/encodings/mac_turkish.py"},{"path":"/usr/lib/python3.12/encodings/mbcs.py"},{"path":"/usr/lib/python3.12/encodings/oem.py"},{"path":"/usr/lib/python3.12/encodings/palmos.py"},{"path":"/usr/lib/python3.12/encodings/ptcp154.py"},{"path":"/usr/lib/python3.12/encodings/punycode.py"},{"path":"/usr/lib/python3.12/encodings/quopri_codec.py"},{"path":"/usr/lib/python3.12/encodings/raw_unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/rot_13.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/shift_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/tis_620.py"},{"path":"/usr/lib/python3.12/encodings/undefined.py"},{"path":"/usr/lib/python3.12/encodings/unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/utf_16.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_32.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_7.py"},{"path":"/usr/lib/python3.12/encodings/utf_8.py"},{"path":"/usr/lib/python3.12/encodings/utf_8_sig.py"},{"path":"/usr/lib/python3.12/encodings/uu_codec.py"},{"path":"/usr/lib/python3.12/encodings/zlib_codec.py"},{"path":"/usr/lib/python3.12/ensurepip"},{"path":"/usr/lib/python3.12/ensurepip/__init__.py"},{"path":"/usr/lib/python3.12/ensurepip/__main__.py"},{"path":"/usr/lib/python3.12/ensurepip/_uninstall.py"},{"path":"/usr/lib/python3.12/ensurepip/_bundled"},{"path":"/usr/lib/python3.12/ensurepip/_bundled/pip-25.0.1-py3-none-any.whl"},{"path":"/usr/lib/python3.12/html"},{"path":"/usr/lib/python3.12/html/__init__.py"},{"path":"/usr/lib/python3.12/html/entities.py"},{"path":"/usr/lib/python3.12/html/parser.py"},{"path":"/usr/lib/python3.12/http"},{"path":"/usr/lib/python3.12/http/__init__.py"},{"path":"/usr/lib/python3.12/http/client.py"},{"path":"/usr/lib/python3.12/http/cookiejar.py"},{"path":"/usr/lib/python3.12/http/cookies.py"},{"path":"/usr/lib/python3.12/http/server.py"},{"path":"/usr/lib/python3.12/importlib"},{"path":"/usr/lib/python3.12/importlib/__init__.py"},{"path":"/usr/lib/python3.12/importlib/_abc.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap_external.py"},{"path":"/usr/lib/python3.12/importlib/abc.py"},{"path":"/usr/lib/python3.12/importlib/machinery.py"},{"path":"/usr/lib/python3.12/importlib/readers.py"},{"path":"/usr/lib/python3.12/importlib/simple.py"},{"path":"/usr/lib/python3.12/importlib/util.py"},{"path":"/usr/lib/python3.12/importlib/metadata"},{"path":"/usr/lib/python3.12/importlib/metadata/__init__.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_collections.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_functools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_meta.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_text.py"},{"path":"/usr/lib/python3.12/importlib/resources"},{"path":"/usr/lib/python3.12/importlib/resources/__init__.py"},{"path":"/usr/lib/python3.12/importlib/resources/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/resources/_common.py"},{"path":"/usr/lib/python3.12/importlib/resources/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/resources/_legacy.py"},{"path":"/usr/lib/python3.12/importlib/resources/abc.py"},{"path":"/usr/lib/python3.12/importlib/resources/readers.py"},{"path":"/usr/lib/python3.12/importlib/resources/simple.py"},{"path":"/usr/lib/python3.12/json"},{"path":"/usr/lib/python3.12/json/__init__.py"},{"path":"/usr/lib/python3.12/json/decoder.py"},{"path":"/usr/lib/python3.12/json/encoder.py"},{"path":"/usr/lib/python3.12/json/scanner.py"},{"path":"/usr/lib/python3.12/json/tool.py"},{"path":"/usr/lib/python3.12/lib-dynload"},{"path":"/usr/lib/python3.12/lib-dynload/_asyncio.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bisect.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_blake2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bz2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_cn.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_hk.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_iso2022.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_jp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_kr.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_tw.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_contextvars.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_crypt.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_csv.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes_test.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses_panel.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_datetime.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_dbm.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_decimal.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_elementtree.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_hashlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_heapq.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_json.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lsprof.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lzma.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_md5.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multibytecodec.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multiprocessing.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_opcode.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_pickle.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixshmem.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixsubprocess.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_queue.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_random.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha1.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_socket.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sqlite3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ssl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_statistics.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_struct.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testbuffer.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testclinic.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testimportmultiple.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testinternalcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testmultiphase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testsinglephase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxinterpchannels.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxsubinterpreters.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxtestfuzz.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_zoneinfo.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/array.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/audioop.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/binascii.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/cmath.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/fcntl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/grp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/math.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/mmap.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/ossaudiodev.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/pyexpat.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/readline.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/resource.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/select.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/spwd.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/syslog.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/termios.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/unicodedata.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited_35.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxsubtype.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/zlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib2to3"},{"path":"/usr/lib/python3.12/lib2to3/Grammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/Grammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/__main__.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_matcher.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_utils.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_base.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_util.py"},{"path":"/usr/lib/python3.12/lib2to3/main.py"},{"path":"/usr/lib/python3.12/lib2to3/patcomp.py"},{"path":"/usr/lib/python3.12/lib2to3/pygram.py"},{"path":"/usr/lib/python3.12/lib2to3/pytree.py"},{"path":"/usr/lib/python3.12/lib2to3/refactor.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes"},{"path":"/usr/lib/python3.12/lib2to3/fixes/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_apply.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_asserts.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_basestring.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_buffer.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_dict.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_except.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exec.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_execfile.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exitfunc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_filter.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_funcattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_future.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_getcwdu.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_has_key.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_idioms.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_import.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports2.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_intern.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_isinstance.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_long.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_map.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_metaclass.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_methodattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ne.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_next.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_nonzero.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_numliterals.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_operator.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_paren.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_print.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raise.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raw_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reduce.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reload.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_renames.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_repr.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_set_literal.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_standarderror.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_sys_exc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_throw.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_tuple_params.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_types.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_unicode.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_urllib.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ws_comma.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xrange.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xreadlines.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_zip.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/conv.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/driver.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/grammar.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/literals.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/parse.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/pgen.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/token.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/tokenize.py"},{"path":"/usr/lib/python3.12/logging"},{"path":"/usr/lib/python3.12/logging/__init__.py"},{"path":"/usr/lib/python3.12/logging/config.py"},{"path":"/usr/lib/python3.12/logging/handlers.py"},{"path":"/usr/lib/python3.12/multiprocessing"},{"path":"/usr/lib/python3.12/multiprocessing/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/connection.py"},{"path":"/usr/lib/python3.12/multiprocessing/context.py"},{"path":"/usr/lib/python3.12/multiprocessing/forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/heap.py"},{"path":"/usr/lib/python3.12/multiprocessing/managers.py"},{"path":"/usr/lib/python3.12/multiprocessing/pool.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_fork.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_posix.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_win32.py"},{"path":"/usr/lib/python3.12/multiprocessing/process.py"},{"path":"/usr/lib/python3.12/multiprocessing/queues.py"},{"path":"/usr/lib/python3.12/multiprocessing/reduction.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_sharer.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_tracker.py"},{"path":"/usr/lib/python3.12/multiprocessing/shared_memory.py"},{"path":"/usr/lib/python3.12/multiprocessing/sharedctypes.py"},{"path":"/usr/lib/python3.12/multiprocessing/spawn.py"},{"path":"/usr/lib/python3.12/multiprocessing/synchronize.py"},{"path":"/usr/lib/python3.12/multiprocessing/util.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/connection.py"},{"path":"/usr/lib/python3.12/pydoc_data"},{"path":"/usr/lib/python3.12/pydoc_data/__init__.py"},{"path":"/usr/lib/python3.12/pydoc_data/_pydoc.css"},{"path":"/usr/lib/python3.12/pydoc_data/topics.py"},{"path":"/usr/lib/python3.12/re"},{"path":"/usr/lib/python3.12/re/__init__.py"},{"path":"/usr/lib/python3.12/re/_casefix.py"},{"path":"/usr/lib/python3.12/re/_compiler.py"},{"path":"/usr/lib/python3.12/re/_constants.py"},{"path":"/usr/lib/python3.12/re/_parser.py"},{"path":"/usr/lib/python3.12/site-packages"},{"path":"/usr/lib/python3.12/site-packages/README.txt"},{"path":"/usr/lib/python3.12/sqlite3"},{"path":"/usr/lib/python3.12/sqlite3/__init__.py"},{"path":"/usr/lib/python3.12/sqlite3/__main__.py"},{"path":"/usr/lib/python3.12/sqlite3/dbapi2.py"},{"path":"/usr/lib/python3.12/sqlite3/dump.py"},{"path":"/usr/lib/python3.12/tomllib"},{"path":"/usr/lib/python3.12/tomllib/__init__.py"},{"path":"/usr/lib/python3.12/tomllib/_parser.py"},{"path":"/usr/lib/python3.12/tomllib/_re.py"},{"path":"/usr/lib/python3.12/tomllib/_types.py"},{"path":"/usr/lib/python3.12/turtledemo"},{"path":"/usr/lib/python3.12/turtledemo/__init__.py"},{"path":"/usr/lib/python3.12/turtledemo/__main__.py"},{"path":"/usr/lib/python3.12/turtledemo/bytedesign.py"},{"path":"/usr/lib/python3.12/turtledemo/chaos.py"},{"path":"/usr/lib/python3.12/turtledemo/clock.py"},{"path":"/usr/lib/python3.12/turtledemo/colormixer.py"},{"path":"/usr/lib/python3.12/turtledemo/forest.py"},{"path":"/usr/lib/python3.12/turtledemo/fractalcurves.py"},{"path":"/usr/lib/python3.12/turtledemo/lindenmayer.py"},{"path":"/usr/lib/python3.12/turtledemo/minimal_hanoi.py"},{"path":"/usr/lib/python3.12/turtledemo/nim.py"},{"path":"/usr/lib/python3.12/turtledemo/paint.py"},{"path":"/usr/lib/python3.12/turtledemo/peace.py"},{"path":"/usr/lib/python3.12/turtledemo/penrose.py"},{"path":"/usr/lib/python3.12/turtledemo/planet_and_moon.py"},{"path":"/usr/lib/python3.12/turtledemo/rosette.py"},{"path":"/usr/lib/python3.12/turtledemo/round_dance.py"},{"path":"/usr/lib/python3.12/turtledemo/sorting_animate.py"},{"path":"/usr/lib/python3.12/turtledemo/tree.py"},{"path":"/usr/lib/python3.12/turtledemo/turtle.cfg"},{"path":"/usr/lib/python3.12/turtledemo/two_canvases.py"},{"path":"/usr/lib/python3.12/turtledemo/yinyang.py"},{"path":"/usr/lib/python3.12/unittest"},{"path":"/usr/lib/python3.12/unittest/__init__.py"},{"path":"/usr/lib/python3.12/unittest/__main__.py"},{"path":"/usr/lib/python3.12/unittest/_log.py"},{"path":"/usr/lib/python3.12/unittest/async_case.py"},{"path":"/usr/lib/python3.12/unittest/case.py"},{"path":"/usr/lib/python3.12/unittest/loader.py"},{"path":"/usr/lib/python3.12/unittest/main.py"},{"path":"/usr/lib/python3.12/unittest/mock.py"},{"path":"/usr/lib/python3.12/unittest/result.py"},{"path":"/usr/lib/python3.12/unittest/runner.py"},{"path":"/usr/lib/python3.12/unittest/signals.py"},{"path":"/usr/lib/python3.12/unittest/suite.py"},{"path":"/usr/lib/python3.12/unittest/util.py"},{"path":"/usr/lib/python3.12/urllib"},{"path":"/usr/lib/python3.12/urllib/__init__.py"},{"path":"/usr/lib/python3.12/urllib/error.py"},{"path":"/usr/lib/python3.12/urllib/parse.py"},{"path":"/usr/lib/python3.12/urllib/request.py"},{"path":"/usr/lib/python3.12/urllib/response.py"},{"path":"/usr/lib/python3.12/urllib/robotparser.py"},{"path":"/usr/lib/python3.12/venv"},{"path":"/usr/lib/python3.12/venv/__init__.py"},{"path":"/usr/lib/python3.12/venv/__main__.py"},{"path":"/usr/lib/python3.12/venv/scripts"},{"path":"/usr/lib/python3.12/venv/scripts/common"},{"path":"/usr/lib/python3.12/venv/scripts/common/Activate.ps1"},{"path":"/usr/lib/python3.12/venv/scripts/common/activate"},{"path":"/usr/lib/python3.12/venv/scripts/posix"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.csh"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.fish"},{"path":"/usr/lib/python3.12/wsgiref"},{"path":"/usr/lib/python3.12/wsgiref/__init__.py"},{"path":"/usr/lib/python3.12/wsgiref/handlers.py"},{"path":"/usr/lib/python3.12/wsgiref/headers.py"},{"path":"/usr/lib/python3.12/wsgiref/simple_server.py"},{"path":"/usr/lib/python3.12/wsgiref/types.py"},{"path":"/usr/lib/python3.12/wsgiref/util.py"},{"path":"/usr/lib/python3.12/wsgiref/validate.py"},{"path":"/usr/lib/python3.12/xml"},{"path":"/usr/lib/python3.12/xml/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom"},{"path":"/usr/lib/python3.12/xml/dom/NodeFilter.py"},{"path":"/usr/lib/python3.12/xml/dom/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom/domreg.py"},{"path":"/usr/lib/python3.12/xml/dom/expatbuilder.py"},{"path":"/usr/lib/python3.12/xml/dom/minicompat.py"},{"path":"/usr/lib/python3.12/xml/dom/minidom.py"},{"path":"/usr/lib/python3.12/xml/dom/pulldom.py"},{"path":"/usr/lib/python3.12/xml/dom/xmlbuilder.py"},{"path":"/usr/lib/python3.12/xml/etree"},{"path":"/usr/lib/python3.12/xml/etree/ElementInclude.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementPath.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementTree.py"},{"path":"/usr/lib/python3.12/xml/etree/__init__.py"},{"path":"/usr/lib/python3.12/xml/etree/cElementTree.py"},{"path":"/usr/lib/python3.12/xml/parsers"},{"path":"/usr/lib/python3.12/xml/parsers/__init__.py"},{"path":"/usr/lib/python3.12/xml/parsers/expat.py"},{"path":"/usr/lib/python3.12/xml/sax"},{"path":"/usr/lib/python3.12/xml/sax/__init__.py"},{"path":"/usr/lib/python3.12/xml/sax/_exceptions.py"},{"path":"/usr/lib/python3.12/xml/sax/expatreader.py"},{"path":"/usr/lib/python3.12/xml/sax/handler.py"},{"path":"/usr/lib/python3.12/xml/sax/saxutils.py"},{"path":"/usr/lib/python3.12/xml/sax/xmlreader.py"},{"path":"/usr/lib/python3.12/xmlrpc"},{"path":"/usr/lib/python3.12/xmlrpc/__init__.py"},{"path":"/usr/lib/python3.12/xmlrpc/client.py"},{"path":"/usr/lib/python3.12/xmlrpc/server.py"},{"path":"/usr/lib/python3.12/zipfile"},{"path":"/usr/lib/python3.12/zipfile/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/__main__.py"},{"path":"/usr/lib/python3.12/zipfile/_path"},{"path":"/usr/lib/python3.12/zipfile/_path/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/_path/glob.py"},{"path":"/usr/lib/python3.12/zoneinfo"},{"path":"/usr/lib/python3.12/zoneinfo/__init__.py"},{"path":"/usr/lib/python3.12/zoneinfo/_common.py"},{"path":"/usr/lib/python3.12/zoneinfo/_tzpath.py"},{"path":"/usr/lib/python3.12/zoneinfo/_zoneinfo.py"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.13.14||>= 3.14.0a1, < 3.14.5rc1||>= 3.15.0a1, < 3.15.0b1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}},{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.13.14||>= 3.14.0a1, < 3.14.5rc1||>= 3.15.0a1, < 3.15.0b1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.26571999999999996,"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"f94b9b7cafe48a8a","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r1:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r1:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"1.7.19-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-67217","versionConstraint":"<= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-67217","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67217","cwe":"CWE-696","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67217","date":"2026-10-08","epss":0.00433,"percentile":0.35564}],"risk":0.24031499999999997,"urls":["https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON_Utils.c#L887-L948","https://joshua.hu/cjson-json-parser-cve-vulnerabilities","https://www.vulncheck.com/advisories/cjson-json-patch-non-atomic-application-destroys-data-before-validation"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67217","description":"cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches."},"relatedVulnerabilities":[]},{"artifact":{"id":"3669047a8bbbd4c1","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vxq7-64xx-v4gw","versionConstraint":">=1.10.3,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-vxq7-64xx-v4gw","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"risk":0.23944000000000001,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw","https://nvd.nist.gov/vuln/detail/CVE-2026-97689","https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vxq7-64xx-v4gw","description":"urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory"},"relatedVulnerabilities":[{"id":"CVE-2026-97689","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"urls":["https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97689","description":"urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59847","versionConstraint":">= 0.9.0, < 0.11.5||= 0.12.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59847","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59847","cwe":"CWE-253","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59847","cwe":"CWE-1310","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59847","date":"2026-10-08","epss":0.00332,"percentile":0.24421}],"risk":0.23571999999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59847","https://bugzilla.redhat.com/show_bug.cgi?id=2498180"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59847","description":"A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection."},"relatedVulnerabilities":[]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59850","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59850","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59850","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59850","date":"2026-10-08","epss":0.00346,"percentile":0.26038}],"risk":0.23182000000000003,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59850","https://bugzilla.redhat.com/show_bug.cgi?id=2498183"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59850","description":"A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"09c24a4342b1cfdb","cpes":["cpe:2.3:a:python-software-foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.12.15-r0:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:apk/alpine/python3@3.12.15-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"3.12.15-r0","language":"","licenses":["PSF-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/2to3"},{"path":"/usr/bin/2to3-3.12"},{"path":"/usr/bin/pydoc3"},{"path":"/usr/bin/pydoc3.12"},{"path":"/usr/bin/python"},{"path":"/usr/bin/python3"},{"path":"/usr/bin/python3.12"},{"path":"/usr/include"},{"path":"/usr/include/python3.12"},{"path":"/usr/include/python3.12/pyconfig.h"},{"path":"/usr/lib"},{"path":"/usr/lib/libpython3.12.so.1.0"},{"path":"/usr/lib/libpython3.so"},{"path":"/usr/lib/python3.12"},{"path":"/usr/lib/python3.12/EXTERNALLY-MANAGED"},{"path":"/usr/lib/python3.12/LICENSE.txt"},{"path":"/usr/lib/python3.12/__future__.py"},{"path":"/usr/lib/python3.12/__hello__.py"},{"path":"/usr/lib/python3.12/_aix_support.py"},{"path":"/usr/lib/python3.12/_collections_abc.py"},{"path":"/usr/lib/python3.12/_compat_pickle.py"},{"path":"/usr/lib/python3.12/_compression.py"},{"path":"/usr/lib/python3.12/_markupbase.py"},{"path":"/usr/lib/python3.12/_osx_support.py"},{"path":"/usr/lib/python3.12/_py_abc.py"},{"path":"/usr/lib/python3.12/_pydatetime.py"},{"path":"/usr/lib/python3.12/_pydecimal.py"},{"path":"/usr/lib/python3.12/_pyio.py"},{"path":"/usr/lib/python3.12/_pylong.py"},{"path":"/usr/lib/python3.12/_sitebuiltins.py"},{"path":"/usr/lib/python3.12/_strptime.py"},{"path":"/usr/lib/python3.12/_sysconfigdata__linux_x86_64-linux-musl.py"},{"path":"/usr/lib/python3.12/_threading_local.py"},{"path":"/usr/lib/python3.12/_weakrefset.py"},{"path":"/usr/lib/python3.12/abc.py"},{"path":"/usr/lib/python3.12/aifc.py"},{"path":"/usr/lib/python3.12/antigravity.py"},{"path":"/usr/lib/python3.12/argparse.py"},{"path":"/usr/lib/python3.12/ast.py"},{"path":"/usr/lib/python3.12/base64.py"},{"path":"/usr/lib/python3.12/bdb.py"},{"path":"/usr/lib/python3.12/bisect.py"},{"path":"/usr/lib/python3.12/bz2.py"},{"path":"/usr/lib/python3.12/cProfile.py"},{"path":"/usr/lib/python3.12/calendar.py"},{"path":"/usr/lib/python3.12/cgi.py"},{"path":"/usr/lib/python3.12/cgitb.py"},{"path":"/usr/lib/python3.12/chunk.py"},{"path":"/usr/lib/python3.12/cmd.py"},{"path":"/usr/lib/python3.12/code.py"},{"path":"/usr/lib/python3.12/codecs.py"},{"path":"/usr/lib/python3.12/codeop.py"},{"path":"/usr/lib/python3.12/colorsys.py"},{"path":"/usr/lib/python3.12/compileall.py"},{"path":"/usr/lib/python3.12/configparser.py"},{"path":"/usr/lib/python3.12/contextlib.py"},{"path":"/usr/lib/python3.12/contextvars.py"},{"path":"/usr/lib/python3.12/copy.py"},{"path":"/usr/lib/python3.12/copyreg.py"},{"path":"/usr/lib/python3.12/crypt.py"},{"path":"/usr/lib/python3.12/csv.py"},{"path":"/usr/lib/python3.12/dataclasses.py"},{"path":"/usr/lib/python3.12/datetime.py"},{"path":"/usr/lib/python3.12/decimal.py"},{"path":"/usr/lib/python3.12/difflib.py"},{"path":"/usr/lib/python3.12/dis.py"},{"path":"/usr/lib/python3.12/doctest.py"},{"path":"/usr/lib/python3.12/enum.py"},{"path":"/usr/lib/python3.12/filecmp.py"},{"path":"/usr/lib/python3.12/fileinput.py"},{"path":"/usr/lib/python3.12/fnmatch.py"},{"path":"/usr/lib/python3.12/fractions.py"},{"path":"/usr/lib/python3.12/ftplib.py"},{"path":"/usr/lib/python3.12/functools.py"},{"path":"/usr/lib/python3.12/genericpath.py"},{"path":"/usr/lib/python3.12/getopt.py"},{"path":"/usr/lib/python3.12/getpass.py"},{"path":"/usr/lib/python3.12/gettext.py"},{"path":"/usr/lib/python3.12/glob.py"},{"path":"/usr/lib/python3.12/graphlib.py"},{"path":"/usr/lib/python3.12/gzip.py"},{"path":"/usr/lib/python3.12/hashlib.py"},{"path":"/usr/lib/python3.12/heapq.py"},{"path":"/usr/lib/python3.12/hmac.py"},{"path":"/usr/lib/python3.12/imaplib.py"},{"path":"/usr/lib/python3.12/imghdr.py"},{"path":"/usr/lib/python3.12/inspect.py"},{"path":"/usr/lib/python3.12/io.py"},{"path":"/usr/lib/python3.12/ipaddress.py"},{"path":"/usr/lib/python3.12/keyword.py"},{"path":"/usr/lib/python3.12/linecache.py"},{"path":"/usr/lib/python3.12/locale.py"},{"path":"/usr/lib/python3.12/lzma.py"},{"path":"/usr/lib/python3.12/mailbox.py"},{"path":"/usr/lib/python3.12/mailcap.py"},{"path":"/usr/lib/python3.12/mimetypes.py"},{"path":"/usr/lib/python3.12/modulefinder.py"},{"path":"/usr/lib/python3.12/netrc.py"},{"path":"/usr/lib/python3.12/nntplib.py"},{"path":"/usr/lib/python3.12/ntpath.py"},{"path":"/usr/lib/python3.12/nturl2path.py"},{"path":"/usr/lib/python3.12/numbers.py"},{"path":"/usr/lib/python3.12/opcode.py"},{"path":"/usr/lib/python3.12/operator.py"},{"path":"/usr/lib/python3.12/optparse.py"},{"path":"/usr/lib/python3.12/os.py"},{"path":"/usr/lib/python3.12/pathlib.py"},{"path":"/usr/lib/python3.12/pdb.py"},{"path":"/usr/lib/python3.12/pickle.py"},{"path":"/usr/lib/python3.12/pickletools.py"},{"path":"/usr/lib/python3.12/pipes.py"},{"path":"/usr/lib/python3.12/pkgutil.py"},{"path":"/usr/lib/python3.12/platform.py"},{"path":"/usr/lib/python3.12/plistlib.py"},{"path":"/usr/lib/python3.12/poplib.py"},{"path":"/usr/lib/python3.12/posixpath.py"},{"path":"/usr/lib/python3.12/pprint.py"},{"path":"/usr/lib/python3.12/profile.py"},{"path":"/usr/lib/python3.12/pstats.py"},{"path":"/usr/lib/python3.12/pty.py"},{"path":"/usr/lib/python3.12/py_compile.py"},{"path":"/usr/lib/python3.12/pyclbr.py"},{"path":"/usr/lib/python3.12/pydoc.py"},{"path":"/usr/lib/python3.12/queue.py"},{"path":"/usr/lib/python3.12/quopri.py"},{"path":"/usr/lib/python3.12/random.py"},{"path":"/usr/lib/python3.12/reprlib.py"},{"path":"/usr/lib/python3.12/rlcompleter.py"},{"path":"/usr/lib/python3.12/runpy.py"},{"path":"/usr/lib/python3.12/sched.py"},{"path":"/usr/lib/python3.12/secrets.py"},{"path":"/usr/lib/python3.12/selectors.py"},{"path":"/usr/lib/python3.12/shelve.py"},{"path":"/usr/lib/python3.12/shlex.py"},{"path":"/usr/lib/python3.12/shutil.py"},{"path":"/usr/lib/python3.12/signal.py"},{"path":"/usr/lib/python3.12/site.py"},{"path":"/usr/lib/python3.12/smtplib.py"},{"path":"/usr/lib/python3.12/sndhdr.py"},{"path":"/usr/lib/python3.12/socket.py"},{"path":"/usr/lib/python3.12/socketserver.py"},{"path":"/usr/lib/python3.12/sre_compile.py"},{"path":"/usr/lib/python3.12/sre_constants.py"},{"path":"/usr/lib/python3.12/sre_parse.py"},{"path":"/usr/lib/python3.12/ssl.py"},{"path":"/usr/lib/python3.12/stat.py"},{"path":"/usr/lib/python3.12/statistics.py"},{"path":"/usr/lib/python3.12/string.py"},{"path":"/usr/lib/python3.12/stringprep.py"},{"path":"/usr/lib/python3.12/struct.py"},{"path":"/usr/lib/python3.12/subprocess.py"},{"path":"/usr/lib/python3.12/sunau.py"},{"path":"/usr/lib/python3.12/symtable.py"},{"path":"/usr/lib/python3.12/sysconfig.py"},{"path":"/usr/lib/python3.12/tabnanny.py"},{"path":"/usr/lib/python3.12/tarfile.py"},{"path":"/usr/lib/python3.12/telnetlib.py"},{"path":"/usr/lib/python3.12/tempfile.py"},{"path":"/usr/lib/python3.12/textwrap.py"},{"path":"/usr/lib/python3.12/this.py"},{"path":"/usr/lib/python3.12/threading.py"},{"path":"/usr/lib/python3.12/timeit.py"},{"path":"/usr/lib/python3.12/token.py"},{"path":"/usr/lib/python3.12/tokenize.py"},{"path":"/usr/lib/python3.12/trace.py"},{"path":"/usr/lib/python3.12/traceback.py"},{"path":"/usr/lib/python3.12/tracemalloc.py"},{"path":"/usr/lib/python3.12/tty.py"},{"path":"/usr/lib/python3.12/turtle.py"},{"path":"/usr/lib/python3.12/types.py"},{"path":"/usr/lib/python3.12/typing.py"},{"path":"/usr/lib/python3.12/uu.py"},{"path":"/usr/lib/python3.12/uuid.py"},{"path":"/usr/lib/python3.12/warnings.py"},{"path":"/usr/lib/python3.12/wave.py"},{"path":"/usr/lib/python3.12/weakref.py"},{"path":"/usr/lib/python3.12/webbrowser.py"},{"path":"/usr/lib/python3.12/xdrlib.py"},{"path":"/usr/lib/python3.12/zipapp.py"},{"path":"/usr/lib/python3.12/zipimport.py"},{"path":"/usr/lib/python3.12/__phello__"},{"path":"/usr/lib/python3.12/__phello__/__init__.py"},{"path":"/usr/lib/python3.12/__phello__/spam.py"},{"path":"/usr/lib/python3.12/asyncio"},{"path":"/usr/lib/python3.12/asyncio/__init__.py"},{"path":"/usr/lib/python3.12/asyncio/__main__.py"},{"path":"/usr/lib/python3.12/asyncio/base_events.py"},{"path":"/usr/lib/python3.12/asyncio/base_futures.py"},{"path":"/usr/lib/python3.12/asyncio/base_subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/base_tasks.py"},{"path":"/usr/lib/python3.12/asyncio/constants.py"},{"path":"/usr/lib/python3.12/asyncio/coroutines.py"},{"path":"/usr/lib/python3.12/asyncio/events.py"},{"path":"/usr/lib/python3.12/asyncio/exceptions.py"},{"path":"/usr/lib/python3.12/asyncio/format_helpers.py"},{"path":"/usr/lib/python3.12/asyncio/futures.py"},{"path":"/usr/lib/python3.12/asyncio/locks.py"},{"path":"/usr/lib/python3.12/asyncio/log.py"},{"path":"/usr/lib/python3.12/asyncio/mixins.py"},{"path":"/usr/lib/python3.12/asyncio/proactor_events.py"},{"path":"/usr/lib/python3.12/asyncio/protocols.py"},{"path":"/usr/lib/python3.12/asyncio/queues.py"},{"path":"/usr/lib/python3.12/asyncio/runners.py"},{"path":"/usr/lib/python3.12/asyncio/selector_events.py"},{"path":"/usr/lib/python3.12/asyncio/sslproto.py"},{"path":"/usr/lib/python3.12/asyncio/staggered.py"},{"path":"/usr/lib/python3.12/asyncio/streams.py"},{"path":"/usr/lib/python3.12/asyncio/subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/taskgroups.py"},{"path":"/usr/lib/python3.12/asyncio/tasks.py"},{"path":"/usr/lib/python3.12/asyncio/threads.py"},{"path":"/usr/lib/python3.12/asyncio/timeouts.py"},{"path":"/usr/lib/python3.12/asyncio/transports.py"},{"path":"/usr/lib/python3.12/asyncio/trsock.py"},{"path":"/usr/lib/python3.12/asyncio/unix_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_utils.py"},{"path":"/usr/lib/python3.12/collections"},{"path":"/usr/lib/python3.12/collections/__init__.py"},{"path":"/usr/lib/python3.12/collections/abc.py"},{"path":"/usr/lib/python3.12/concurrent"},{"path":"/usr/lib/python3.12/concurrent/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures"},{"path":"/usr/lib/python3.12/concurrent/futures/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures/_base.py"},{"path":"/usr/lib/python3.12/concurrent/futures/process.py"},{"path":"/usr/lib/python3.12/concurrent/futures/thread.py"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Makefile"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.bootstrap"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.local"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.stdlib"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/config.c.in"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/install-sh"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/makesetup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/python-config.py"},{"path":"/usr/lib/python3.12/ctypes"},{"path":"/usr/lib/python3.12/ctypes/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/_aix.py"},{"path":"/usr/lib/python3.12/ctypes/_endian.py"},{"path":"/usr/lib/python3.12/ctypes/util.py"},{"path":"/usr/lib/python3.12/ctypes/wintypes.py"},{"path":"/usr/lib/python3.12/ctypes/macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/README.ctypes"},{"path":"/usr/lib/python3.12/ctypes/macholib/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dyld.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dylib.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib.bat"},{"path":"/usr/lib/python3.12/ctypes/macholib/framework.py"},{"path":"/usr/lib/python3.12/curses"},{"path":"/usr/lib/python3.12/curses/__init__.py"},{"path":"/usr/lib/python3.12/curses/ascii.py"},{"path":"/usr/lib/python3.12/curses/has_key.py"},{"path":"/usr/lib/python3.12/curses/panel.py"},{"path":"/usr/lib/python3.12/curses/textpad.py"},{"path":"/usr/lib/python3.12/dbm"},{"path":"/usr/lib/python3.12/dbm/__init__.py"},{"path":"/usr/lib/python3.12/dbm/dumb.py"},{"path":"/usr/lib/python3.12/dbm/gnu.py"},{"path":"/usr/lib/python3.12/dbm/ndbm.py"},{"path":"/usr/lib/python3.12/email"},{"path":"/usr/lib/python3.12/email/__init__.py"},{"path":"/usr/lib/python3.12/email/_encoded_words.py"},{"path":"/usr/lib/python3.12/email/_header_value_parser.py"},{"path":"/usr/lib/python3.12/email/_parseaddr.py"},{"path":"/usr/lib/python3.12/email/_policybase.py"},{"path":"/usr/lib/python3.12/email/architecture.rst"},{"path":"/usr/lib/python3.12/email/base64mime.py"},{"path":"/usr/lib/python3.12/email/charset.py"},{"path":"/usr/lib/python3.12/email/contentmanager.py"},{"path":"/usr/lib/python3.12/email/encoders.py"},{"path":"/usr/lib/python3.12/email/errors.py"},{"path":"/usr/lib/python3.12/email/feedparser.py"},{"path":"/usr/lib/python3.12/email/generator.py"},{"path":"/usr/lib/python3.12/email/header.py"},{"path":"/usr/lib/python3.12/email/headerregistry.py"},{"path":"/usr/lib/python3.12/email/iterators.py"},{"path":"/usr/lib/python3.12/email/message.py"},{"path":"/usr/lib/python3.12/email/parser.py"},{"path":"/usr/lib/python3.12/email/policy.py"},{"path":"/usr/lib/python3.12/email/quoprimime.py"},{"path":"/usr/lib/python3.12/email/utils.py"},{"path":"/usr/lib/python3.12/email/mime"},{"path":"/usr/lib/python3.12/email/mime/__init__.py"},{"path":"/usr/lib/python3.12/email/mime/application.py"},{"path":"/usr/lib/python3.12/email/mime/audio.py"},{"path":"/usr/lib/python3.12/email/mime/base.py"},{"path":"/usr/lib/python3.12/email/mime/image.py"},{"path":"/usr/lib/python3.12/email/mime/message.py"},{"path":"/usr/lib/python3.12/email/mime/multipart.py"},{"path":"/usr/lib/python3.12/email/mime/nonmultipart.py"},{"path":"/usr/lib/python3.12/email/mime/text.py"},{"path":"/usr/lib/python3.12/encodings"},{"path":"/usr/lib/python3.12/encodings/__init__.py"},{"path":"/usr/lib/python3.12/encodings/aliases.py"},{"path":"/usr/lib/python3.12/encodings/ascii.py"},{"path":"/usr/lib/python3.12/encodings/base64_codec.py"},{"path":"/usr/lib/python3.12/encodings/big5.py"},{"path":"/usr/lib/python3.12/encodings/big5hkscs.py"},{"path":"/usr/lib/python3.12/encodings/bz2_codec.py"},{"path":"/usr/lib/python3.12/encodings/charmap.py"},{"path":"/usr/lib/python3.12/encodings/cp037.py"},{"path":"/usr/lib/python3.12/encodings/cp1006.py"},{"path":"/usr/lib/python3.12/encodings/cp1026.py"},{"path":"/usr/lib/python3.12/encodings/cp1125.py"},{"path":"/usr/lib/python3.12/encodings/cp1140.py"},{"path":"/usr/lib/python3.12/encodings/cp1250.py"},{"path":"/usr/lib/python3.12/encodings/cp1251.py"},{"path":"/usr/lib/python3.12/encodings/cp1252.py"},{"path":"/usr/lib/python3.12/encodings/cp1253.py"},{"path":"/usr/lib/python3.12/encodings/cp1254.py"},{"path":"/usr/lib/python3.12/encodings/cp1255.py"},{"path":"/usr/lib/python3.12/encodings/cp1256.py"},{"path":"/usr/lib/python3.12/encodings/cp1257.py"},{"path":"/usr/lib/python3.12/encodings/cp1258.py"},{"path":"/usr/lib/python3.12/encodings/cp273.py"},{"path":"/usr/lib/python3.12/encodings/cp424.py"},{"path":"/usr/lib/python3.12/encodings/cp437.py"},{"path":"/usr/lib/python3.12/encodings/cp500.py"},{"path":"/usr/lib/python3.12/encodings/cp720.py"},{"path":"/usr/lib/python3.12/encodings/cp737.py"},{"path":"/usr/lib/python3.12/encodings/cp775.py"},{"path":"/usr/lib/python3.12/encodings/cp850.py"},{"path":"/usr/lib/python3.12/encodings/cp852.py"},{"path":"/usr/lib/python3.12/encodings/cp855.py"},{"path":"/usr/lib/python3.12/encodings/cp856.py"},{"path":"/usr/lib/python3.12/encodings/cp857.py"},{"path":"/usr/lib/python3.12/encodings/cp858.py"},{"path":"/usr/lib/python3.12/encodings/cp860.py"},{"path":"/usr/lib/python3.12/encodings/cp861.py"},{"path":"/usr/lib/python3.12/encodings/cp862.py"},{"path":"/usr/lib/python3.12/encodings/cp863.py"},{"path":"/usr/lib/python3.12/encodings/cp864.py"},{"path":"/usr/lib/python3.12/encodings/cp865.py"},{"path":"/usr/lib/python3.12/encodings/cp866.py"},{"path":"/usr/lib/python3.12/encodings/cp869.py"},{"path":"/usr/lib/python3.12/encodings/cp874.py"},{"path":"/usr/lib/python3.12/encodings/cp875.py"},{"path":"/usr/lib/python3.12/encodings/cp932.py"},{"path":"/usr/lib/python3.12/encodings/cp949.py"},{"path":"/usr/lib/python3.12/encodings/cp950.py"},{"path":"/usr/lib/python3.12/encodings/euc_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/euc_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/euc_jp.py"},{"path":"/usr/lib/python3.12/encodings/euc_kr.py"},{"path":"/usr/lib/python3.12/encodings/gb18030.py"},{"path":"/usr/lib/python3.12/encodings/gb2312.py"},{"path":"/usr/lib/python3.12/encodings/gbk.py"},{"path":"/usr/lib/python3.12/encodings/hex_codec.py"},{"path":"/usr/lib/python3.12/encodings/hp_roman8.py"},{"path":"/usr/lib/python3.12/encodings/hz.py"},{"path":"/usr/lib/python3.12/encodings/idna.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_1.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2004.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_3.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_ext.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_kr.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_1.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_10.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_11.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_13.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_14.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_15.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_16.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_2.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_3.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_4.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_5.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_6.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_7.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_8.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_9.py"},{"path":"/usr/lib/python3.12/encodings/johab.py"},{"path":"/usr/lib/python3.12/encodings/koi8_r.py"},{"path":"/usr/lib/python3.12/encodings/koi8_t.py"},{"path":"/usr/lib/python3.12/encodings/koi8_u.py"},{"path":"/usr/lib/python3.12/encodings/kz1048.py"},{"path":"/usr/lib/python3.12/encodings/latin_1.py"},{"path":"/usr/lib/python3.12/encodings/mac_arabic.py"},{"path":"/usr/lib/python3.12/encodings/mac_croatian.py"},{"path":"/usr/lib/python3.12/encodings/mac_cyrillic.py"},{"path":"/usr/lib/python3.12/encodings/mac_farsi.py"},{"path":"/usr/lib/python3.12/encodings/mac_greek.py"},{"path":"/usr/lib/python3.12/encodings/mac_iceland.py"},{"path":"/usr/lib/python3.12/encodings/mac_latin2.py"},{"path":"/usr/lib/python3.12/encodings/mac_roman.py"},{"path":"/usr/lib/python3.12/encodings/mac_romanian.py"},{"path":"/usr/lib/python3.12/encodings/mac_turkish.py"},{"path":"/usr/lib/python3.12/encodings/mbcs.py"},{"path":"/usr/lib/python3.12/encodings/oem.py"},{"path":"/usr/lib/python3.12/encodings/palmos.py"},{"path":"/usr/lib/python3.12/encodings/ptcp154.py"},{"path":"/usr/lib/python3.12/encodings/punycode.py"},{"path":"/usr/lib/python3.12/encodings/quopri_codec.py"},{"path":"/usr/lib/python3.12/encodings/raw_unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/rot_13.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/shift_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/tis_620.py"},{"path":"/usr/lib/python3.12/encodings/undefined.py"},{"path":"/usr/lib/python3.12/encodings/unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/utf_16.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_32.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_7.py"},{"path":"/usr/lib/python3.12/encodings/utf_8.py"},{"path":"/usr/lib/python3.12/encodings/utf_8_sig.py"},{"path":"/usr/lib/python3.12/encodings/uu_codec.py"},{"path":"/usr/lib/python3.12/encodings/zlib_codec.py"},{"path":"/usr/lib/python3.12/ensurepip"},{"path":"/usr/lib/python3.12/ensurepip/__init__.py"},{"path":"/usr/lib/python3.12/ensurepip/__main__.py"},{"path":"/usr/lib/python3.12/ensurepip/_uninstall.py"},{"path":"/usr/lib/python3.12/ensurepip/_bundled"},{"path":"/usr/lib/python3.12/ensurepip/_bundled/pip-25.0.1-py3-none-any.whl"},{"path":"/usr/lib/python3.12/html"},{"path":"/usr/lib/python3.12/html/__init__.py"},{"path":"/usr/lib/python3.12/html/entities.py"},{"path":"/usr/lib/python3.12/html/parser.py"},{"path":"/usr/lib/python3.12/http"},{"path":"/usr/lib/python3.12/http/__init__.py"},{"path":"/usr/lib/python3.12/http/client.py"},{"path":"/usr/lib/python3.12/http/cookiejar.py"},{"path":"/usr/lib/python3.12/http/cookies.py"},{"path":"/usr/lib/python3.12/http/server.py"},{"path":"/usr/lib/python3.12/importlib"},{"path":"/usr/lib/python3.12/importlib/__init__.py"},{"path":"/usr/lib/python3.12/importlib/_abc.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap_external.py"},{"path":"/usr/lib/python3.12/importlib/abc.py"},{"path":"/usr/lib/python3.12/importlib/machinery.py"},{"path":"/usr/lib/python3.12/importlib/readers.py"},{"path":"/usr/lib/python3.12/importlib/simple.py"},{"path":"/usr/lib/python3.12/importlib/util.py"},{"path":"/usr/lib/python3.12/importlib/metadata"},{"path":"/usr/lib/python3.12/importlib/metadata/__init__.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_collections.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_functools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_meta.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_text.py"},{"path":"/usr/lib/python3.12/importlib/resources"},{"path":"/usr/lib/python3.12/importlib/resources/__init__.py"},{"path":"/usr/lib/python3.12/importlib/resources/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/resources/_common.py"},{"path":"/usr/lib/python3.12/importlib/resources/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/resources/_legacy.py"},{"path":"/usr/lib/python3.12/importlib/resources/abc.py"},{"path":"/usr/lib/python3.12/importlib/resources/readers.py"},{"path":"/usr/lib/python3.12/importlib/resources/simple.py"},{"path":"/usr/lib/python3.12/json"},{"path":"/usr/lib/python3.12/json/__init__.py"},{"path":"/usr/lib/python3.12/json/decoder.py"},{"path":"/usr/lib/python3.12/json/encoder.py"},{"path":"/usr/lib/python3.12/json/scanner.py"},{"path":"/usr/lib/python3.12/json/tool.py"},{"path":"/usr/lib/python3.12/lib-dynload"},{"path":"/usr/lib/python3.12/lib-dynload/_asyncio.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bisect.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_blake2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bz2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_cn.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_hk.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_iso2022.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_jp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_kr.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_tw.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_contextvars.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_crypt.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_csv.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes_test.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses_panel.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_datetime.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_dbm.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_decimal.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_elementtree.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_hashlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_heapq.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_json.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lsprof.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lzma.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_md5.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multibytecodec.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multiprocessing.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_opcode.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_pickle.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixshmem.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixsubprocess.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_queue.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_random.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha1.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_socket.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sqlite3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ssl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_statistics.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_struct.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testbuffer.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testclinic.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testimportmultiple.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testinternalcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testmultiphase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testsinglephase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxinterpchannels.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxsubinterpreters.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxtestfuzz.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_zoneinfo.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/array.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/audioop.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/binascii.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/cmath.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/fcntl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/grp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/math.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/mmap.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/ossaudiodev.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/pyexpat.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/readline.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/resource.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/select.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/spwd.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/syslog.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/termios.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/unicodedata.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited_35.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxsubtype.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/zlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib2to3"},{"path":"/usr/lib/python3.12/lib2to3/Grammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/Grammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/__main__.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_matcher.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_utils.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_base.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_util.py"},{"path":"/usr/lib/python3.12/lib2to3/main.py"},{"path":"/usr/lib/python3.12/lib2to3/patcomp.py"},{"path":"/usr/lib/python3.12/lib2to3/pygram.py"},{"path":"/usr/lib/python3.12/lib2to3/pytree.py"},{"path":"/usr/lib/python3.12/lib2to3/refactor.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes"},{"path":"/usr/lib/python3.12/lib2to3/fixes/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_apply.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_asserts.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_basestring.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_buffer.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_dict.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_except.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exec.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_execfile.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exitfunc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_filter.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_funcattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_future.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_getcwdu.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_has_key.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_idioms.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_import.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports2.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_intern.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_isinstance.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_long.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_map.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_metaclass.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_methodattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ne.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_next.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_nonzero.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_numliterals.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_operator.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_paren.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_print.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raise.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raw_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reduce.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reload.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_renames.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_repr.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_set_literal.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_standarderror.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_sys_exc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_throw.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_tuple_params.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_types.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_unicode.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_urllib.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ws_comma.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xrange.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xreadlines.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_zip.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/conv.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/driver.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/grammar.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/literals.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/parse.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/pgen.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/token.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/tokenize.py"},{"path":"/usr/lib/python3.12/logging"},{"path":"/usr/lib/python3.12/logging/__init__.py"},{"path":"/usr/lib/python3.12/logging/config.py"},{"path":"/usr/lib/python3.12/logging/handlers.py"},{"path":"/usr/lib/python3.12/multiprocessing"},{"path":"/usr/lib/python3.12/multiprocessing/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/connection.py"},{"path":"/usr/lib/python3.12/multiprocessing/context.py"},{"path":"/usr/lib/python3.12/multiprocessing/forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/heap.py"},{"path":"/usr/lib/python3.12/multiprocessing/managers.py"},{"path":"/usr/lib/python3.12/multiprocessing/pool.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_fork.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_posix.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_win32.py"},{"path":"/usr/lib/python3.12/multiprocessing/process.py"},{"path":"/usr/lib/python3.12/multiprocessing/queues.py"},{"path":"/usr/lib/python3.12/multiprocessing/reduction.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_sharer.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_tracker.py"},{"path":"/usr/lib/python3.12/multiprocessing/shared_memory.py"},{"path":"/usr/lib/python3.12/multiprocessing/sharedctypes.py"},{"path":"/usr/lib/python3.12/multiprocessing/spawn.py"},{"path":"/usr/lib/python3.12/multiprocessing/synchronize.py"},{"path":"/usr/lib/python3.12/multiprocessing/util.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/connection.py"},{"path":"/usr/lib/python3.12/pydoc_data"},{"path":"/usr/lib/python3.12/pydoc_data/__init__.py"},{"path":"/usr/lib/python3.12/pydoc_data/_pydoc.css"},{"path":"/usr/lib/python3.12/pydoc_data/topics.py"},{"path":"/usr/lib/python3.12/re"},{"path":"/usr/lib/python3.12/re/__init__.py"},{"path":"/usr/lib/python3.12/re/_casefix.py"},{"path":"/usr/lib/python3.12/re/_compiler.py"},{"path":"/usr/lib/python3.12/re/_constants.py"},{"path":"/usr/lib/python3.12/re/_parser.py"},{"path":"/usr/lib/python3.12/site-packages"},{"path":"/usr/lib/python3.12/site-packages/README.txt"},{"path":"/usr/lib/python3.12/sqlite3"},{"path":"/usr/lib/python3.12/sqlite3/__init__.py"},{"path":"/usr/lib/python3.12/sqlite3/__main__.py"},{"path":"/usr/lib/python3.12/sqlite3/dbapi2.py"},{"path":"/usr/lib/python3.12/sqlite3/dump.py"},{"path":"/usr/lib/python3.12/tomllib"},{"path":"/usr/lib/python3.12/tomllib/__init__.py"},{"path":"/usr/lib/python3.12/tomllib/_parser.py"},{"path":"/usr/lib/python3.12/tomllib/_re.py"},{"path":"/usr/lib/python3.12/tomllib/_types.py"},{"path":"/usr/lib/python3.12/turtledemo"},{"path":"/usr/lib/python3.12/turtledemo/__init__.py"},{"path":"/usr/lib/python3.12/turtledemo/__main__.py"},{"path":"/usr/lib/python3.12/turtledemo/bytedesign.py"},{"path":"/usr/lib/python3.12/turtledemo/chaos.py"},{"path":"/usr/lib/python3.12/turtledemo/clock.py"},{"path":"/usr/lib/python3.12/turtledemo/colormixer.py"},{"path":"/usr/lib/python3.12/turtledemo/forest.py"},{"path":"/usr/lib/python3.12/turtledemo/fractalcurves.py"},{"path":"/usr/lib/python3.12/turtledemo/lindenmayer.py"},{"path":"/usr/lib/python3.12/turtledemo/minimal_hanoi.py"},{"path":"/usr/lib/python3.12/turtledemo/nim.py"},{"path":"/usr/lib/python3.12/turtledemo/paint.py"},{"path":"/usr/lib/python3.12/turtledemo/peace.py"},{"path":"/usr/lib/python3.12/turtledemo/penrose.py"},{"path":"/usr/lib/python3.12/turtledemo/planet_and_moon.py"},{"path":"/usr/lib/python3.12/turtledemo/rosette.py"},{"path":"/usr/lib/python3.12/turtledemo/round_dance.py"},{"path":"/usr/lib/python3.12/turtledemo/sorting_animate.py"},{"path":"/usr/lib/python3.12/turtledemo/tree.py"},{"path":"/usr/lib/python3.12/turtledemo/turtle.cfg"},{"path":"/usr/lib/python3.12/turtledemo/two_canvases.py"},{"path":"/usr/lib/python3.12/turtledemo/yinyang.py"},{"path":"/usr/lib/python3.12/unittest"},{"path":"/usr/lib/python3.12/unittest/__init__.py"},{"path":"/usr/lib/python3.12/unittest/__main__.py"},{"path":"/usr/lib/python3.12/unittest/_log.py"},{"path":"/usr/lib/python3.12/unittest/async_case.py"},{"path":"/usr/lib/python3.12/unittest/case.py"},{"path":"/usr/lib/python3.12/unittest/loader.py"},{"path":"/usr/lib/python3.12/unittest/main.py"},{"path":"/usr/lib/python3.12/unittest/mock.py"},{"path":"/usr/lib/python3.12/unittest/result.py"},{"path":"/usr/lib/python3.12/unittest/runner.py"},{"path":"/usr/lib/python3.12/unittest/signals.py"},{"path":"/usr/lib/python3.12/unittest/suite.py"},{"path":"/usr/lib/python3.12/unittest/util.py"},{"path":"/usr/lib/python3.12/urllib"},{"path":"/usr/lib/python3.12/urllib/__init__.py"},{"path":"/usr/lib/python3.12/urllib/error.py"},{"path":"/usr/lib/python3.12/urllib/parse.py"},{"path":"/usr/lib/python3.12/urllib/request.py"},{"path":"/usr/lib/python3.12/urllib/response.py"},{"path":"/usr/lib/python3.12/urllib/robotparser.py"},{"path":"/usr/lib/python3.12/venv"},{"path":"/usr/lib/python3.12/venv/__init__.py"},{"path":"/usr/lib/python3.12/venv/__main__.py"},{"path":"/usr/lib/python3.12/venv/scripts"},{"path":"/usr/lib/python3.12/venv/scripts/common"},{"path":"/usr/lib/python3.12/venv/scripts/common/Activate.ps1"},{"path":"/usr/lib/python3.12/venv/scripts/common/activate"},{"path":"/usr/lib/python3.12/venv/scripts/posix"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.csh"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.fish"},{"path":"/usr/lib/python3.12/wsgiref"},{"path":"/usr/lib/python3.12/wsgiref/__init__.py"},{"path":"/usr/lib/python3.12/wsgiref/handlers.py"},{"path":"/usr/lib/python3.12/wsgiref/headers.py"},{"path":"/usr/lib/python3.12/wsgiref/simple_server.py"},{"path":"/usr/lib/python3.12/wsgiref/types.py"},{"path":"/usr/lib/python3.12/wsgiref/util.py"},{"path":"/usr/lib/python3.12/wsgiref/validate.py"},{"path":"/usr/lib/python3.12/xml"},{"path":"/usr/lib/python3.12/xml/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom"},{"path":"/usr/lib/python3.12/xml/dom/NodeFilter.py"},{"path":"/usr/lib/python3.12/xml/dom/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom/domreg.py"},{"path":"/usr/lib/python3.12/xml/dom/expatbuilder.py"},{"path":"/usr/lib/python3.12/xml/dom/minicompat.py"},{"path":"/usr/lib/python3.12/xml/dom/minidom.py"},{"path":"/usr/lib/python3.12/xml/dom/pulldom.py"},{"path":"/usr/lib/python3.12/xml/dom/xmlbuilder.py"},{"path":"/usr/lib/python3.12/xml/etree"},{"path":"/usr/lib/python3.12/xml/etree/ElementInclude.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementPath.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementTree.py"},{"path":"/usr/lib/python3.12/xml/etree/__init__.py"},{"path":"/usr/lib/python3.12/xml/etree/cElementTree.py"},{"path":"/usr/lib/python3.12/xml/parsers"},{"path":"/usr/lib/python3.12/xml/parsers/__init__.py"},{"path":"/usr/lib/python3.12/xml/parsers/expat.py"},{"path":"/usr/lib/python3.12/xml/sax"},{"path":"/usr/lib/python3.12/xml/sax/__init__.py"},{"path":"/usr/lib/python3.12/xml/sax/_exceptions.py"},{"path":"/usr/lib/python3.12/xml/sax/expatreader.py"},{"path":"/usr/lib/python3.12/xml/sax/handler.py"},{"path":"/usr/lib/python3.12/xml/sax/saxutils.py"},{"path":"/usr/lib/python3.12/xml/sax/xmlreader.py"},{"path":"/usr/lib/python3.12/xmlrpc"},{"path":"/usr/lib/python3.12/xmlrpc/__init__.py"},{"path":"/usr/lib/python3.12/xmlrpc/client.py"},{"path":"/usr/lib/python3.12/xmlrpc/server.py"},{"path":"/usr/lib/python3.12/zipfile"},{"path":"/usr/lib/python3.12/zipfile/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/__main__.py"},{"path":"/usr/lib/python3.12/zipfile/_path"},{"path":"/usr/lib/python3.12/zipfile/_path/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/_path/glob.py"},{"path":"/usr/lib/python3.12/zoneinfo"},{"path":"/usr/lib/python3.12/zoneinfo/__init__.py"},{"path":"/usr/lib/python3.12/zoneinfo/_common.py"},{"path":"/usr/lib/python3.12/zoneinfo/_tzpath.py"},{"path":"/usr/lib/python3.12/zoneinfo/_zoneinfo.py"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15366","versionConstraint":"< 3.13.15||>= 3.14.0, < 3.14.7||>= 3.15.0a1, < 3.15.0a6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}},{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15366","versionConstraint":"< 3.13.15||>= 3.14.0, < 3.14.7||>= 3.15.0a1, < 3.15.0a6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.22999,"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22921","versionConstraint":"= 7.0||= 7.0.1||= 7.0.2||= 7.0.3||= 7.1||= 7.1-dev||= 7.1.1||= 7.1.2||= 7.1.3||= 7.2-dev||= 8.0||= 8.0.1||= 8.1-dev (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22921","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22921","date":"2026-10-08","epss":0.00372,"percentile":0.29047}],"risk":0.21389999999999998,"urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22921","versionConstraint":"= 7.0||= 7.0.1||= 7.0.2||= 7.0.3||= 7.1||= 7.1-dev||= 7.1.1||= 7.1.2||= 7.1.3||= 7.2-dev||= 8.0||= 8.0.1||= 8.1-dev (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22921","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22921","date":"2026-10-08","epss":0.00372,"percentile":0.29047}],"risk":0.21389999999999998,"urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22921","versionConstraint":"= 7.0||= 7.0.1||= 7.0.2||= 7.0.3||= 7.1||= 7.1-dev||= 7.1.1||= 7.1.2||= 7.1.3||= 7.2-dev||= 8.0||= 8.0.1||= 8.1-dev (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22921","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22921","date":"2026-10-08","epss":0.00372,"percentile":0.29047}],"risk":0.21389999999999998,"urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22921","versionConstraint":"= 7.0||= 7.0.1||= 7.0.2||= 7.0.3||= 7.1||= 7.1-dev||= 7.1.1||= 7.1.2||= 7.1.3||= 7.2-dev||= 8.0||= 8.0.1||= 8.1-dev (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22921","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22921","date":"2026-10-08","epss":0.00372,"percentile":0.29047}],"risk":0.21389999999999998,"urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22921","versionConstraint":"= 7.0||= 7.0.1||= 7.0.2||= 7.0.3||= 7.1||= 7.1-dev||= 7.1.1||= 7.1.2||= 7.1.3||= 7.2-dev||= 8.0||= 8.0.1||= 8.1-dev (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22921","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22921","date":"2026-10-08","epss":0.00372,"percentile":0.29047}],"risk":0.21389999999999998,"urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22921","versionConstraint":"= 7.0||= 7.0.1||= 7.0.2||= 7.0.3||= 7.1||= 7.1-dev||= 7.1.1||= 7.1.2||= 7.1.3||= 7.2-dev||= 8.0||= 8.0.1||= 8.1-dev (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22921","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22921","date":"2026-10-08","epss":0.00372,"percentile":0.29047}],"risk":0.21389999999999998,"urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22921","versionConstraint":"= 7.0||= 7.0.1||= 7.0.2||= 7.0.3||= 7.1||= 7.1-dev||= 7.1.1||= 7.1.2||= 7.1.3||= 7.2-dev||= 8.0||= 8.0.1||= 8.1-dev (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22921","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22921","date":"2026-10-08","epss":0.00372,"percentile":0.29047}],"risk":0.21389999999999998,"urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22921","versionConstraint":"= 7.0||= 7.0.1||= 7.0.2||= 7.0.3||= 7.1||= 7.1-dev||= 7.1.1||= 7.1.2||= 7.1.3||= 7.2-dev||= 8.0||= 8.0.1||= 8.1-dev (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22921","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22921","date":"2026-10-08","epss":0.00372,"percentile":0.29047}],"risk":0.21389999999999998,"urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"63ce02368fd4862f","cpes":["cpe:2.3:a:python-werkzeug:python-werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python-werkzeug:python_werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python_werkzeug:python-werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python_werkzeug:python_werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python-werkzeug:werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python_werkzeug:werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:werkzeug:python-werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:werkzeug:python_werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python:python-werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python:python_werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:werkzeug:werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python:werkzeug:3.1.8:*:*:*:*:*:*:*"],"name":"werkzeug","purl":"pkg:pypi/werkzeug@3.1.8","type":"python","version":"3.1.8","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/bazarr/bin/libs/werkzeug-3.1.8.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/werkzeug-3.1.8.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/werkzeug-3.1.8.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/werkzeug-3.1.8.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.1.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g6x2-hccm-hh4m","versionConstraint":"<3.1.9 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"werkzeug","version":"3.1.8"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-g6x2-hccm-hh4m","fix":{"state":"fixed","versions":["3.1.9"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"3.1.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102598","cwe":"CWE-67","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102598","date":"2026-10-08","epss":0.00368,"percentile":0.28622}],"risk":0.20792,"urls":["https://github.com/pallets/werkzeug/security/advisories/GHSA-g6x2-hccm-hh4m","https://nvd.nist.gov/vuln/detail/CVE-2026-102598","https://github.com/pallets/werkzeug/pull/3309","https://github.com/pallets/werkzeug/commit/8d77320bcdf3a34941ec06dcf16b03c065cd21b6","https://github.com/pallets/werkzeug/releases/tag/3.1.9"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g6x2-hccm-hh4m","description":"Werkzeug safe_join() allows Windows special device names"},"relatedVulnerabilities":[{"id":"CVE-2026-102598","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102598","cwe":"CWE-67","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102598","date":"2026-10-08","epss":0.00368,"percentile":0.28622}],"urls":["https://github.com/pallets/werkzeug/commit/8d77320bcdf3a34941ec06dcf16b03c065cd21b6","https://github.com/pallets/werkzeug/pull/3309","https://github.com/pallets/werkzeug/releases/tag/3.1.9","https://github.com/pallets/werkzeug/security/advisories/GHSA-g6x2-hccm-hh4m"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102598","description":"Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9."}]},{"artifact":{"id":"32ffa7b6269f7621","cpes":["cpe:2.3:a:mike_bayer_project:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_project:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayerproject:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayerproject:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_project:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_project:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_project:mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mikeproject:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mikeproject:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:python-mako:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:python-mako:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:python_mako:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:python_mako:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayerproject:mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:python:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:python:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_project:mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mako:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mako:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike:python-mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike:python_mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mikeproject:mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:python-mako:mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:python_mako:mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer:mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:python:mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mako:mako:1.3.12:*:*:*:*:*:*:*","cpe:2.3:a:mike:mako:1.3.12:*:*:*:*:*:*:*"],"name":"mako","purl":"pkg:pypi/mako@1.3.12","type":"python","version":"1.3.12","language":"python","licenses":["MIT"],"locations":[{"path":"/app/bazarr/bin/libs/mako-1.3.12.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/mako-1.3.12.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/mako-1.3.12.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/mako-1.3.12.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/app/bazarr/bin/libs/mako-1.3.12.dist-info/top_level.txt","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/mako-1.3.12.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.4.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5639-2j2p-m4mx","versionConstraint":"<=1.4.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"mako","version":"1.3.12"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-5639-2j2p-m4mx","fix":{"state":"fixed","versions":["1.4.2"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.4.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102991","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102991","date":"2026-10-08","epss":0.00356,"percentile":0.27232}],"risk":0.20469999999999997,"urls":["https://github.com/sqlalchemy/mako/security/advisories/GHSA-5639-2j2p-m4mx","https://nvd.nist.gov/vuln/detail/CVE-2026-102991","https://github.com/sqlalchemy/mako/issues/441","https://github.com/sqlalchemy/mako/commit/000ed85e4e48771eff460bf4fc721fb43de80e08","https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5639-2j2p-m4mx","description":"Mako: Path traversal via drive-letter URI on Windows in TemplateLookup"},"relatedVulnerabilities":[{"id":"CVE-2026-102991","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102991","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102991","date":"2026-10-08","epss":0.00356,"percentile":0.27232}],"urls":["https://github.com/sqlalchemy/mako/commit/000ed85e4e48771eff460bf4fc721fb43de80e08","https://github.com/sqlalchemy/mako/issues/441","https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2","https://github.com/sqlalchemy/mako/security/advisories/GHSA-5639-2j2p-m4mx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102991","description":"Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with os.path, which uses ntpath. A URI beginning with a drive designator causes ntpath to absorb the traversal segments before the leading dot-dot check, while posixpath resolution can escape the configured template directory. An application that passes attacker-controlled template names or include paths can disclose process-readable files on the same volume, and a targeted file containing Mako template syntax may also be parsed and executed as a template. Raw URL paths are generally normalized before reaching this form, but query strings, form or JSON bodies, route parameters, and dynamic include expressions can preserve it. This issue is fixed in version 1.4.2."}]},{"artifact":{"id":"f94b9b7cafe48a8a","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r1:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r1:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"1.7.19-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-16554","versionConstraint":"= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-16554","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16554","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16554","date":"2026-10-08","epss":0.00291,"percentile":0.19897}],"risk":0.2029725,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-16554","https://github.com/DaveGamble/cJSON","http://www.openwall.com/lists/oss-security/2026/07/30/26","http://www.openwall.com/lists/oss-security/2026/07/31/4"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16554","description":"cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation. An attacker supplying a crafted JSON string to an application using cJSON on a 32-bit platform can cause a heap buffer overflow, potentially leading to remote code execution, information disclosure, or denial of service.\n\n\n\n\nBecause project creator contact attempts were unsuccessful, the vulnerability has only been confirmed in version 1.7.19 but may also affect other versions."},"relatedVulnerabilities":[]},{"artifact":{"id":"746a5398c68762fd","cpes":["cpe:2.3:a:coreutils:coreutils:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.8-r1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.8-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"9.8-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/chcon"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/runcon"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.8:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.8-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"80fc7e85cd2608c5","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.8-r1:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.8-r1?arch=x86_64&distro=alpine-3.23.6&upstream=coreutils","type":"apk","version":"9.8-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.8:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.8-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"68b3fbeb4ac465f1","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.8-r1:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.8-r1?arch=x86_64&distro=alpine-3.23.6&upstream=coreutils","type":"apk","version":"9.8-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.8:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.8-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"b7fbe9298b523216","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.8-r1:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.8-r1?arch=x86_64&distro=alpine-3.23.6&upstream=coreutils","type":"apk","version":"9.8-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.8:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.8-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"09c24a4342b1cfdb","cpes":["cpe:2.3:a:python-software-foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.12.15-r0:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:apk/alpine/python3@3.12.15-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"3.12.15-r0","language":"","licenses":["PSF-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/2to3"},{"path":"/usr/bin/2to3-3.12"},{"path":"/usr/bin/pydoc3"},{"path":"/usr/bin/pydoc3.12"},{"path":"/usr/bin/python"},{"path":"/usr/bin/python3"},{"path":"/usr/bin/python3.12"},{"path":"/usr/include"},{"path":"/usr/include/python3.12"},{"path":"/usr/include/python3.12/pyconfig.h"},{"path":"/usr/lib"},{"path":"/usr/lib/libpython3.12.so.1.0"},{"path":"/usr/lib/libpython3.so"},{"path":"/usr/lib/python3.12"},{"path":"/usr/lib/python3.12/EXTERNALLY-MANAGED"},{"path":"/usr/lib/python3.12/LICENSE.txt"},{"path":"/usr/lib/python3.12/__future__.py"},{"path":"/usr/lib/python3.12/__hello__.py"},{"path":"/usr/lib/python3.12/_aix_support.py"},{"path":"/usr/lib/python3.12/_collections_abc.py"},{"path":"/usr/lib/python3.12/_compat_pickle.py"},{"path":"/usr/lib/python3.12/_compression.py"},{"path":"/usr/lib/python3.12/_markupbase.py"},{"path":"/usr/lib/python3.12/_osx_support.py"},{"path":"/usr/lib/python3.12/_py_abc.py"},{"path":"/usr/lib/python3.12/_pydatetime.py"},{"path":"/usr/lib/python3.12/_pydecimal.py"},{"path":"/usr/lib/python3.12/_pyio.py"},{"path":"/usr/lib/python3.12/_pylong.py"},{"path":"/usr/lib/python3.12/_sitebuiltins.py"},{"path":"/usr/lib/python3.12/_strptime.py"},{"path":"/usr/lib/python3.12/_sysconfigdata__linux_x86_64-linux-musl.py"},{"path":"/usr/lib/python3.12/_threading_local.py"},{"path":"/usr/lib/python3.12/_weakrefset.py"},{"path":"/usr/lib/python3.12/abc.py"},{"path":"/usr/lib/python3.12/aifc.py"},{"path":"/usr/lib/python3.12/antigravity.py"},{"path":"/usr/lib/python3.12/argparse.py"},{"path":"/usr/lib/python3.12/ast.py"},{"path":"/usr/lib/python3.12/base64.py"},{"path":"/usr/lib/python3.12/bdb.py"},{"path":"/usr/lib/python3.12/bisect.py"},{"path":"/usr/lib/python3.12/bz2.py"},{"path":"/usr/lib/python3.12/cProfile.py"},{"path":"/usr/lib/python3.12/calendar.py"},{"path":"/usr/lib/python3.12/cgi.py"},{"path":"/usr/lib/python3.12/cgitb.py"},{"path":"/usr/lib/python3.12/chunk.py"},{"path":"/usr/lib/python3.12/cmd.py"},{"path":"/usr/lib/python3.12/code.py"},{"path":"/usr/lib/python3.12/codecs.py"},{"path":"/usr/lib/python3.12/codeop.py"},{"path":"/usr/lib/python3.12/colorsys.py"},{"path":"/usr/lib/python3.12/compileall.py"},{"path":"/usr/lib/python3.12/configparser.py"},{"path":"/usr/lib/python3.12/contextlib.py"},{"path":"/usr/lib/python3.12/contextvars.py"},{"path":"/usr/lib/python3.12/copy.py"},{"path":"/usr/lib/python3.12/copyreg.py"},{"path":"/usr/lib/python3.12/crypt.py"},{"path":"/usr/lib/python3.12/csv.py"},{"path":"/usr/lib/python3.12/dataclasses.py"},{"path":"/usr/lib/python3.12/datetime.py"},{"path":"/usr/lib/python3.12/decimal.py"},{"path":"/usr/lib/python3.12/difflib.py"},{"path":"/usr/lib/python3.12/dis.py"},{"path":"/usr/lib/python3.12/doctest.py"},{"path":"/usr/lib/python3.12/enum.py"},{"path":"/usr/lib/python3.12/filecmp.py"},{"path":"/usr/lib/python3.12/fileinput.py"},{"path":"/usr/lib/python3.12/fnmatch.py"},{"path":"/usr/lib/python3.12/fractions.py"},{"path":"/usr/lib/python3.12/ftplib.py"},{"path":"/usr/lib/python3.12/functools.py"},{"path":"/usr/lib/python3.12/genericpath.py"},{"path":"/usr/lib/python3.12/getopt.py"},{"path":"/usr/lib/python3.12/getpass.py"},{"path":"/usr/lib/python3.12/gettext.py"},{"path":"/usr/lib/python3.12/glob.py"},{"path":"/usr/lib/python3.12/graphlib.py"},{"path":"/usr/lib/python3.12/gzip.py"},{"path":"/usr/lib/python3.12/hashlib.py"},{"path":"/usr/lib/python3.12/heapq.py"},{"path":"/usr/lib/python3.12/hmac.py"},{"path":"/usr/lib/python3.12/imaplib.py"},{"path":"/usr/lib/python3.12/imghdr.py"},{"path":"/usr/lib/python3.12/inspect.py"},{"path":"/usr/lib/python3.12/io.py"},{"path":"/usr/lib/python3.12/ipaddress.py"},{"path":"/usr/lib/python3.12/keyword.py"},{"path":"/usr/lib/python3.12/linecache.py"},{"path":"/usr/lib/python3.12/locale.py"},{"path":"/usr/lib/python3.12/lzma.py"},{"path":"/usr/lib/python3.12/mailbox.py"},{"path":"/usr/lib/python3.12/mailcap.py"},{"path":"/usr/lib/python3.12/mimetypes.py"},{"path":"/usr/lib/python3.12/modulefinder.py"},{"path":"/usr/lib/python3.12/netrc.py"},{"path":"/usr/lib/python3.12/nntplib.py"},{"path":"/usr/lib/python3.12/ntpath.py"},{"path":"/usr/lib/python3.12/nturl2path.py"},{"path":"/usr/lib/python3.12/numbers.py"},{"path":"/usr/lib/python3.12/opcode.py"},{"path":"/usr/lib/python3.12/operator.py"},{"path":"/usr/lib/python3.12/optparse.py"},{"path":"/usr/lib/python3.12/os.py"},{"path":"/usr/lib/python3.12/pathlib.py"},{"path":"/usr/lib/python3.12/pdb.py"},{"path":"/usr/lib/python3.12/pickle.py"},{"path":"/usr/lib/python3.12/pickletools.py"},{"path":"/usr/lib/python3.12/pipes.py"},{"path":"/usr/lib/python3.12/pkgutil.py"},{"path":"/usr/lib/python3.12/platform.py"},{"path":"/usr/lib/python3.12/plistlib.py"},{"path":"/usr/lib/python3.12/poplib.py"},{"path":"/usr/lib/python3.12/posixpath.py"},{"path":"/usr/lib/python3.12/pprint.py"},{"path":"/usr/lib/python3.12/profile.py"},{"path":"/usr/lib/python3.12/pstats.py"},{"path":"/usr/lib/python3.12/pty.py"},{"path":"/usr/lib/python3.12/py_compile.py"},{"path":"/usr/lib/python3.12/pyclbr.py"},{"path":"/usr/lib/python3.12/pydoc.py"},{"path":"/usr/lib/python3.12/queue.py"},{"path":"/usr/lib/python3.12/quopri.py"},{"path":"/usr/lib/python3.12/random.py"},{"path":"/usr/lib/python3.12/reprlib.py"},{"path":"/usr/lib/python3.12/rlcompleter.py"},{"path":"/usr/lib/python3.12/runpy.py"},{"path":"/usr/lib/python3.12/sched.py"},{"path":"/usr/lib/python3.12/secrets.py"},{"path":"/usr/lib/python3.12/selectors.py"},{"path":"/usr/lib/python3.12/shelve.py"},{"path":"/usr/lib/python3.12/shlex.py"},{"path":"/usr/lib/python3.12/shutil.py"},{"path":"/usr/lib/python3.12/signal.py"},{"path":"/usr/lib/python3.12/site.py"},{"path":"/usr/lib/python3.12/smtplib.py"},{"path":"/usr/lib/python3.12/sndhdr.py"},{"path":"/usr/lib/python3.12/socket.py"},{"path":"/usr/lib/python3.12/socketserver.py"},{"path":"/usr/lib/python3.12/sre_compile.py"},{"path":"/usr/lib/python3.12/sre_constants.py"},{"path":"/usr/lib/python3.12/sre_parse.py"},{"path":"/usr/lib/python3.12/ssl.py"},{"path":"/usr/lib/python3.12/stat.py"},{"path":"/usr/lib/python3.12/statistics.py"},{"path":"/usr/lib/python3.12/string.py"},{"path":"/usr/lib/python3.12/stringprep.py"},{"path":"/usr/lib/python3.12/struct.py"},{"path":"/usr/lib/python3.12/subprocess.py"},{"path":"/usr/lib/python3.12/sunau.py"},{"path":"/usr/lib/python3.12/symtable.py"},{"path":"/usr/lib/python3.12/sysconfig.py"},{"path":"/usr/lib/python3.12/tabnanny.py"},{"path":"/usr/lib/python3.12/tarfile.py"},{"path":"/usr/lib/python3.12/telnetlib.py"},{"path":"/usr/lib/python3.12/tempfile.py"},{"path":"/usr/lib/python3.12/textwrap.py"},{"path":"/usr/lib/python3.12/this.py"},{"path":"/usr/lib/python3.12/threading.py"},{"path":"/usr/lib/python3.12/timeit.py"},{"path":"/usr/lib/python3.12/token.py"},{"path":"/usr/lib/python3.12/tokenize.py"},{"path":"/usr/lib/python3.12/trace.py"},{"path":"/usr/lib/python3.12/traceback.py"},{"path":"/usr/lib/python3.12/tracemalloc.py"},{"path":"/usr/lib/python3.12/tty.py"},{"path":"/usr/lib/python3.12/turtle.py"},{"path":"/usr/lib/python3.12/types.py"},{"path":"/usr/lib/python3.12/typing.py"},{"path":"/usr/lib/python3.12/uu.py"},{"path":"/usr/lib/python3.12/uuid.py"},{"path":"/usr/lib/python3.12/warnings.py"},{"path":"/usr/lib/python3.12/wave.py"},{"path":"/usr/lib/python3.12/weakref.py"},{"path":"/usr/lib/python3.12/webbrowser.py"},{"path":"/usr/lib/python3.12/xdrlib.py"},{"path":"/usr/lib/python3.12/zipapp.py"},{"path":"/usr/lib/python3.12/zipimport.py"},{"path":"/usr/lib/python3.12/__phello__"},{"path":"/usr/lib/python3.12/__phello__/__init__.py"},{"path":"/usr/lib/python3.12/__phello__/spam.py"},{"path":"/usr/lib/python3.12/asyncio"},{"path":"/usr/lib/python3.12/asyncio/__init__.py"},{"path":"/usr/lib/python3.12/asyncio/__main__.py"},{"path":"/usr/lib/python3.12/asyncio/base_events.py"},{"path":"/usr/lib/python3.12/asyncio/base_futures.py"},{"path":"/usr/lib/python3.12/asyncio/base_subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/base_tasks.py"},{"path":"/usr/lib/python3.12/asyncio/constants.py"},{"path":"/usr/lib/python3.12/asyncio/coroutines.py"},{"path":"/usr/lib/python3.12/asyncio/events.py"},{"path":"/usr/lib/python3.12/asyncio/exceptions.py"},{"path":"/usr/lib/python3.12/asyncio/format_helpers.py"},{"path":"/usr/lib/python3.12/asyncio/futures.py"},{"path":"/usr/lib/python3.12/asyncio/locks.py"},{"path":"/usr/lib/python3.12/asyncio/log.py"},{"path":"/usr/lib/python3.12/asyncio/mixins.py"},{"path":"/usr/lib/python3.12/asyncio/proactor_events.py"},{"path":"/usr/lib/python3.12/asyncio/protocols.py"},{"path":"/usr/lib/python3.12/asyncio/queues.py"},{"path":"/usr/lib/python3.12/asyncio/runners.py"},{"path":"/usr/lib/python3.12/asyncio/selector_events.py"},{"path":"/usr/lib/python3.12/asyncio/sslproto.py"},{"path":"/usr/lib/python3.12/asyncio/staggered.py"},{"path":"/usr/lib/python3.12/asyncio/streams.py"},{"path":"/usr/lib/python3.12/asyncio/subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/taskgroups.py"},{"path":"/usr/lib/python3.12/asyncio/tasks.py"},{"path":"/usr/lib/python3.12/asyncio/threads.py"},{"path":"/usr/lib/python3.12/asyncio/timeouts.py"},{"path":"/usr/lib/python3.12/asyncio/transports.py"},{"path":"/usr/lib/python3.12/asyncio/trsock.py"},{"path":"/usr/lib/python3.12/asyncio/unix_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_utils.py"},{"path":"/usr/lib/python3.12/collections"},{"path":"/usr/lib/python3.12/collections/__init__.py"},{"path":"/usr/lib/python3.12/collections/abc.py"},{"path":"/usr/lib/python3.12/concurrent"},{"path":"/usr/lib/python3.12/concurrent/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures"},{"path":"/usr/lib/python3.12/concurrent/futures/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures/_base.py"},{"path":"/usr/lib/python3.12/concurrent/futures/process.py"},{"path":"/usr/lib/python3.12/concurrent/futures/thread.py"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Makefile"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.bootstrap"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.local"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.stdlib"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/config.c.in"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/install-sh"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/makesetup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/python-config.py"},{"path":"/usr/lib/python3.12/ctypes"},{"path":"/usr/lib/python3.12/ctypes/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/_aix.py"},{"path":"/usr/lib/python3.12/ctypes/_endian.py"},{"path":"/usr/lib/python3.12/ctypes/util.py"},{"path":"/usr/lib/python3.12/ctypes/wintypes.py"},{"path":"/usr/lib/python3.12/ctypes/macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/README.ctypes"},{"path":"/usr/lib/python3.12/ctypes/macholib/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dyld.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dylib.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib.bat"},{"path":"/usr/lib/python3.12/ctypes/macholib/framework.py"},{"path":"/usr/lib/python3.12/curses"},{"path":"/usr/lib/python3.12/curses/__init__.py"},{"path":"/usr/lib/python3.12/curses/ascii.py"},{"path":"/usr/lib/python3.12/curses/has_key.py"},{"path":"/usr/lib/python3.12/curses/panel.py"},{"path":"/usr/lib/python3.12/curses/textpad.py"},{"path":"/usr/lib/python3.12/dbm"},{"path":"/usr/lib/python3.12/dbm/__init__.py"},{"path":"/usr/lib/python3.12/dbm/dumb.py"},{"path":"/usr/lib/python3.12/dbm/gnu.py"},{"path":"/usr/lib/python3.12/dbm/ndbm.py"},{"path":"/usr/lib/python3.12/email"},{"path":"/usr/lib/python3.12/email/__init__.py"},{"path":"/usr/lib/python3.12/email/_encoded_words.py"},{"path":"/usr/lib/python3.12/email/_header_value_parser.py"},{"path":"/usr/lib/python3.12/email/_parseaddr.py"},{"path":"/usr/lib/python3.12/email/_policybase.py"},{"path":"/usr/lib/python3.12/email/architecture.rst"},{"path":"/usr/lib/python3.12/email/base64mime.py"},{"path":"/usr/lib/python3.12/email/charset.py"},{"path":"/usr/lib/python3.12/email/contentmanager.py"},{"path":"/usr/lib/python3.12/email/encoders.py"},{"path":"/usr/lib/python3.12/email/errors.py"},{"path":"/usr/lib/python3.12/email/feedparser.py"},{"path":"/usr/lib/python3.12/email/generator.py"},{"path":"/usr/lib/python3.12/email/header.py"},{"path":"/usr/lib/python3.12/email/headerregistry.py"},{"path":"/usr/lib/python3.12/email/iterators.py"},{"path":"/usr/lib/python3.12/email/message.py"},{"path":"/usr/lib/python3.12/email/parser.py"},{"path":"/usr/lib/python3.12/email/policy.py"},{"path":"/usr/lib/python3.12/email/quoprimime.py"},{"path":"/usr/lib/python3.12/email/utils.py"},{"path":"/usr/lib/python3.12/email/mime"},{"path":"/usr/lib/python3.12/email/mime/__init__.py"},{"path":"/usr/lib/python3.12/email/mime/application.py"},{"path":"/usr/lib/python3.12/email/mime/audio.py"},{"path":"/usr/lib/python3.12/email/mime/base.py"},{"path":"/usr/lib/python3.12/email/mime/image.py"},{"path":"/usr/lib/python3.12/email/mime/message.py"},{"path":"/usr/lib/python3.12/email/mime/multipart.py"},{"path":"/usr/lib/python3.12/email/mime/nonmultipart.py"},{"path":"/usr/lib/python3.12/email/mime/text.py"},{"path":"/usr/lib/python3.12/encodings"},{"path":"/usr/lib/python3.12/encodings/__init__.py"},{"path":"/usr/lib/python3.12/encodings/aliases.py"},{"path":"/usr/lib/python3.12/encodings/ascii.py"},{"path":"/usr/lib/python3.12/encodings/base64_codec.py"},{"path":"/usr/lib/python3.12/encodings/big5.py"},{"path":"/usr/lib/python3.12/encodings/big5hkscs.py"},{"path":"/usr/lib/python3.12/encodings/bz2_codec.py"},{"path":"/usr/lib/python3.12/encodings/charmap.py"},{"path":"/usr/lib/python3.12/encodings/cp037.py"},{"path":"/usr/lib/python3.12/encodings/cp1006.py"},{"path":"/usr/lib/python3.12/encodings/cp1026.py"},{"path":"/usr/lib/python3.12/encodings/cp1125.py"},{"path":"/usr/lib/python3.12/encodings/cp1140.py"},{"path":"/usr/lib/python3.12/encodings/cp1250.py"},{"path":"/usr/lib/python3.12/encodings/cp1251.py"},{"path":"/usr/lib/python3.12/encodings/cp1252.py"},{"path":"/usr/lib/python3.12/encodings/cp1253.py"},{"path":"/usr/lib/python3.12/encodings/cp1254.py"},{"path":"/usr/lib/python3.12/encodings/cp1255.py"},{"path":"/usr/lib/python3.12/encodings/cp1256.py"},{"path":"/usr/lib/python3.12/encodings/cp1257.py"},{"path":"/usr/lib/python3.12/encodings/cp1258.py"},{"path":"/usr/lib/python3.12/encodings/cp273.py"},{"path":"/usr/lib/python3.12/encodings/cp424.py"},{"path":"/usr/lib/python3.12/encodings/cp437.py"},{"path":"/usr/lib/python3.12/encodings/cp500.py"},{"path":"/usr/lib/python3.12/encodings/cp720.py"},{"path":"/usr/lib/python3.12/encodings/cp737.py"},{"path":"/usr/lib/python3.12/encodings/cp775.py"},{"path":"/usr/lib/python3.12/encodings/cp850.py"},{"path":"/usr/lib/python3.12/encodings/cp852.py"},{"path":"/usr/lib/python3.12/encodings/cp855.py"},{"path":"/usr/lib/python3.12/encodings/cp856.py"},{"path":"/usr/lib/python3.12/encodings/cp857.py"},{"path":"/usr/lib/python3.12/encodings/cp858.py"},{"path":"/usr/lib/python3.12/encodings/cp860.py"},{"path":"/usr/lib/python3.12/encodings/cp861.py"},{"path":"/usr/lib/python3.12/encodings/cp862.py"},{"path":"/usr/lib/python3.12/encodings/cp863.py"},{"path":"/usr/lib/python3.12/encodings/cp864.py"},{"path":"/usr/lib/python3.12/encodings/cp865.py"},{"path":"/usr/lib/python3.12/encodings/cp866.py"},{"path":"/usr/lib/python3.12/encodings/cp869.py"},{"path":"/usr/lib/python3.12/encodings/cp874.py"},{"path":"/usr/lib/python3.12/encodings/cp875.py"},{"path":"/usr/lib/python3.12/encodings/cp932.py"},{"path":"/usr/lib/python3.12/encodings/cp949.py"},{"path":"/usr/lib/python3.12/encodings/cp950.py"},{"path":"/usr/lib/python3.12/encodings/euc_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/euc_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/euc_jp.py"},{"path":"/usr/lib/python3.12/encodings/euc_kr.py"},{"path":"/usr/lib/python3.12/encodings/gb18030.py"},{"path":"/usr/lib/python3.12/encodings/gb2312.py"},{"path":"/usr/lib/python3.12/encodings/gbk.py"},{"path":"/usr/lib/python3.12/encodings/hex_codec.py"},{"path":"/usr/lib/python3.12/encodings/hp_roman8.py"},{"path":"/usr/lib/python3.12/encodings/hz.py"},{"path":"/usr/lib/python3.12/encodings/idna.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_1.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2004.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_3.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_ext.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_kr.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_1.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_10.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_11.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_13.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_14.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_15.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_16.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_2.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_3.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_4.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_5.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_6.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_7.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_8.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_9.py"},{"path":"/usr/lib/python3.12/encodings/johab.py"},{"path":"/usr/lib/python3.12/encodings/koi8_r.py"},{"path":"/usr/lib/python3.12/encodings/koi8_t.py"},{"path":"/usr/lib/python3.12/encodings/koi8_u.py"},{"path":"/usr/lib/python3.12/encodings/kz1048.py"},{"path":"/usr/lib/python3.12/encodings/latin_1.py"},{"path":"/usr/lib/python3.12/encodings/mac_arabic.py"},{"path":"/usr/lib/python3.12/encodings/mac_croatian.py"},{"path":"/usr/lib/python3.12/encodings/mac_cyrillic.py"},{"path":"/usr/lib/python3.12/encodings/mac_farsi.py"},{"path":"/usr/lib/python3.12/encodings/mac_greek.py"},{"path":"/usr/lib/python3.12/encodings/mac_iceland.py"},{"path":"/usr/lib/python3.12/encodings/mac_latin2.py"},{"path":"/usr/lib/python3.12/encodings/mac_roman.py"},{"path":"/usr/lib/python3.12/encodings/mac_romanian.py"},{"path":"/usr/lib/python3.12/encodings/mac_turkish.py"},{"path":"/usr/lib/python3.12/encodings/mbcs.py"},{"path":"/usr/lib/python3.12/encodings/oem.py"},{"path":"/usr/lib/python3.12/encodings/palmos.py"},{"path":"/usr/lib/python3.12/encodings/ptcp154.py"},{"path":"/usr/lib/python3.12/encodings/punycode.py"},{"path":"/usr/lib/python3.12/encodings/quopri_codec.py"},{"path":"/usr/lib/python3.12/encodings/raw_unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/rot_13.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/shift_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/tis_620.py"},{"path":"/usr/lib/python3.12/encodings/undefined.py"},{"path":"/usr/lib/python3.12/encodings/unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/utf_16.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_32.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_7.py"},{"path":"/usr/lib/python3.12/encodings/utf_8.py"},{"path":"/usr/lib/python3.12/encodings/utf_8_sig.py"},{"path":"/usr/lib/python3.12/encodings/uu_codec.py"},{"path":"/usr/lib/python3.12/encodings/zlib_codec.py"},{"path":"/usr/lib/python3.12/ensurepip"},{"path":"/usr/lib/python3.12/ensurepip/__init__.py"},{"path":"/usr/lib/python3.12/ensurepip/__main__.py"},{"path":"/usr/lib/python3.12/ensurepip/_uninstall.py"},{"path":"/usr/lib/python3.12/ensurepip/_bundled"},{"path":"/usr/lib/python3.12/ensurepip/_bundled/pip-25.0.1-py3-none-any.whl"},{"path":"/usr/lib/python3.12/html"},{"path":"/usr/lib/python3.12/html/__init__.py"},{"path":"/usr/lib/python3.12/html/entities.py"},{"path":"/usr/lib/python3.12/html/parser.py"},{"path":"/usr/lib/python3.12/http"},{"path":"/usr/lib/python3.12/http/__init__.py"},{"path":"/usr/lib/python3.12/http/client.py"},{"path":"/usr/lib/python3.12/http/cookiejar.py"},{"path":"/usr/lib/python3.12/http/cookies.py"},{"path":"/usr/lib/python3.12/http/server.py"},{"path":"/usr/lib/python3.12/importlib"},{"path":"/usr/lib/python3.12/importlib/__init__.py"},{"path":"/usr/lib/python3.12/importlib/_abc.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap_external.py"},{"path":"/usr/lib/python3.12/importlib/abc.py"},{"path":"/usr/lib/python3.12/importlib/machinery.py"},{"path":"/usr/lib/python3.12/importlib/readers.py"},{"path":"/usr/lib/python3.12/importlib/simple.py"},{"path":"/usr/lib/python3.12/importlib/util.py"},{"path":"/usr/lib/python3.12/importlib/metadata"},{"path":"/usr/lib/python3.12/importlib/metadata/__init__.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_collections.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_functools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_meta.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_text.py"},{"path":"/usr/lib/python3.12/importlib/resources"},{"path":"/usr/lib/python3.12/importlib/resources/__init__.py"},{"path":"/usr/lib/python3.12/importlib/resources/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/resources/_common.py"},{"path":"/usr/lib/python3.12/importlib/resources/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/resources/_legacy.py"},{"path":"/usr/lib/python3.12/importlib/resources/abc.py"},{"path":"/usr/lib/python3.12/importlib/resources/readers.py"},{"path":"/usr/lib/python3.12/importlib/resources/simple.py"},{"path":"/usr/lib/python3.12/json"},{"path":"/usr/lib/python3.12/json/__init__.py"},{"path":"/usr/lib/python3.12/json/decoder.py"},{"path":"/usr/lib/python3.12/json/encoder.py"},{"path":"/usr/lib/python3.12/json/scanner.py"},{"path":"/usr/lib/python3.12/json/tool.py"},{"path":"/usr/lib/python3.12/lib-dynload"},{"path":"/usr/lib/python3.12/lib-dynload/_asyncio.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bisect.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_blake2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bz2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_cn.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_hk.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_iso2022.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_jp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_kr.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_tw.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_contextvars.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_crypt.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_csv.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes_test.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses_panel.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_datetime.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_dbm.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_decimal.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_elementtree.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_hashlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_heapq.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_json.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lsprof.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lzma.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_md5.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multibytecodec.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multiprocessing.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_opcode.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_pickle.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixshmem.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixsubprocess.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_queue.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_random.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha1.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_socket.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sqlite3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ssl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_statistics.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_struct.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testbuffer.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testclinic.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testimportmultiple.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testinternalcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testmultiphase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testsinglephase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxinterpchannels.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxsubinterpreters.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxtestfuzz.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_zoneinfo.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/array.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/audioop.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/binascii.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/cmath.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/fcntl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/grp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/math.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/mmap.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/ossaudiodev.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/pyexpat.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/readline.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/resource.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/select.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/spwd.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/syslog.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/termios.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/unicodedata.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited_35.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxsubtype.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/zlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib2to3"},{"path":"/usr/lib/python3.12/lib2to3/Grammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/Grammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/__main__.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_matcher.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_utils.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_base.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_util.py"},{"path":"/usr/lib/python3.12/lib2to3/main.py"},{"path":"/usr/lib/python3.12/lib2to3/patcomp.py"},{"path":"/usr/lib/python3.12/lib2to3/pygram.py"},{"path":"/usr/lib/python3.12/lib2to3/pytree.py"},{"path":"/usr/lib/python3.12/lib2to3/refactor.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes"},{"path":"/usr/lib/python3.12/lib2to3/fixes/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_apply.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_asserts.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_basestring.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_buffer.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_dict.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_except.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exec.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_execfile.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exitfunc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_filter.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_funcattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_future.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_getcwdu.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_has_key.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_idioms.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_import.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports2.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_intern.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_isinstance.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_long.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_map.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_metaclass.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_methodattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ne.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_next.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_nonzero.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_numliterals.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_operator.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_paren.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_print.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raise.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raw_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reduce.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reload.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_renames.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_repr.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_set_literal.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_standarderror.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_sys_exc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_throw.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_tuple_params.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_types.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_unicode.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_urllib.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ws_comma.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xrange.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xreadlines.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_zip.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/conv.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/driver.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/grammar.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/literals.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/parse.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/pgen.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/token.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/tokenize.py"},{"path":"/usr/lib/python3.12/logging"},{"path":"/usr/lib/python3.12/logging/__init__.py"},{"path":"/usr/lib/python3.12/logging/config.py"},{"path":"/usr/lib/python3.12/logging/handlers.py"},{"path":"/usr/lib/python3.12/multiprocessing"},{"path":"/usr/lib/python3.12/multiprocessing/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/connection.py"},{"path":"/usr/lib/python3.12/multiprocessing/context.py"},{"path":"/usr/lib/python3.12/multiprocessing/forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/heap.py"},{"path":"/usr/lib/python3.12/multiprocessing/managers.py"},{"path":"/usr/lib/python3.12/multiprocessing/pool.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_fork.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_posix.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_win32.py"},{"path":"/usr/lib/python3.12/multiprocessing/process.py"},{"path":"/usr/lib/python3.12/multiprocessing/queues.py"},{"path":"/usr/lib/python3.12/multiprocessing/reduction.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_sharer.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_tracker.py"},{"path":"/usr/lib/python3.12/multiprocessing/shared_memory.py"},{"path":"/usr/lib/python3.12/multiprocessing/sharedctypes.py"},{"path":"/usr/lib/python3.12/multiprocessing/spawn.py"},{"path":"/usr/lib/python3.12/multiprocessing/synchronize.py"},{"path":"/usr/lib/python3.12/multiprocessing/util.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/connection.py"},{"path":"/usr/lib/python3.12/pydoc_data"},{"path":"/usr/lib/python3.12/pydoc_data/__init__.py"},{"path":"/usr/lib/python3.12/pydoc_data/_pydoc.css"},{"path":"/usr/lib/python3.12/pydoc_data/topics.py"},{"path":"/usr/lib/python3.12/re"},{"path":"/usr/lib/python3.12/re/__init__.py"},{"path":"/usr/lib/python3.12/re/_casefix.py"},{"path":"/usr/lib/python3.12/re/_compiler.py"},{"path":"/usr/lib/python3.12/re/_constants.py"},{"path":"/usr/lib/python3.12/re/_parser.py"},{"path":"/usr/lib/python3.12/site-packages"},{"path":"/usr/lib/python3.12/site-packages/README.txt"},{"path":"/usr/lib/python3.12/sqlite3"},{"path":"/usr/lib/python3.12/sqlite3/__init__.py"},{"path":"/usr/lib/python3.12/sqlite3/__main__.py"},{"path":"/usr/lib/python3.12/sqlite3/dbapi2.py"},{"path":"/usr/lib/python3.12/sqlite3/dump.py"},{"path":"/usr/lib/python3.12/tomllib"},{"path":"/usr/lib/python3.12/tomllib/__init__.py"},{"path":"/usr/lib/python3.12/tomllib/_parser.py"},{"path":"/usr/lib/python3.12/tomllib/_re.py"},{"path":"/usr/lib/python3.12/tomllib/_types.py"},{"path":"/usr/lib/python3.12/turtledemo"},{"path":"/usr/lib/python3.12/turtledemo/__init__.py"},{"path":"/usr/lib/python3.12/turtledemo/__main__.py"},{"path":"/usr/lib/python3.12/turtledemo/bytedesign.py"},{"path":"/usr/lib/python3.12/turtledemo/chaos.py"},{"path":"/usr/lib/python3.12/turtledemo/clock.py"},{"path":"/usr/lib/python3.12/turtledemo/colormixer.py"},{"path":"/usr/lib/python3.12/turtledemo/forest.py"},{"path":"/usr/lib/python3.12/turtledemo/fractalcurves.py"},{"path":"/usr/lib/python3.12/turtledemo/lindenmayer.py"},{"path":"/usr/lib/python3.12/turtledemo/minimal_hanoi.py"},{"path":"/usr/lib/python3.12/turtledemo/nim.py"},{"path":"/usr/lib/python3.12/turtledemo/paint.py"},{"path":"/usr/lib/python3.12/turtledemo/peace.py"},{"path":"/usr/lib/python3.12/turtledemo/penrose.py"},{"path":"/usr/lib/python3.12/turtledemo/planet_and_moon.py"},{"path":"/usr/lib/python3.12/turtledemo/rosette.py"},{"path":"/usr/lib/python3.12/turtledemo/round_dance.py"},{"path":"/usr/lib/python3.12/turtledemo/sorting_animate.py"},{"path":"/usr/lib/python3.12/turtledemo/tree.py"},{"path":"/usr/lib/python3.12/turtledemo/turtle.cfg"},{"path":"/usr/lib/python3.12/turtledemo/two_canvases.py"},{"path":"/usr/lib/python3.12/turtledemo/yinyang.py"},{"path":"/usr/lib/python3.12/unittest"},{"path":"/usr/lib/python3.12/unittest/__init__.py"},{"path":"/usr/lib/python3.12/unittest/__main__.py"},{"path":"/usr/lib/python3.12/unittest/_log.py"},{"path":"/usr/lib/python3.12/unittest/async_case.py"},{"path":"/usr/lib/python3.12/unittest/case.py"},{"path":"/usr/lib/python3.12/unittest/loader.py"},{"path":"/usr/lib/python3.12/unittest/main.py"},{"path":"/usr/lib/python3.12/unittest/mock.py"},{"path":"/usr/lib/python3.12/unittest/result.py"},{"path":"/usr/lib/python3.12/unittest/runner.py"},{"path":"/usr/lib/python3.12/unittest/signals.py"},{"path":"/usr/lib/python3.12/unittest/suite.py"},{"path":"/usr/lib/python3.12/unittest/util.py"},{"path":"/usr/lib/python3.12/urllib"},{"path":"/usr/lib/python3.12/urllib/__init__.py"},{"path":"/usr/lib/python3.12/urllib/error.py"},{"path":"/usr/lib/python3.12/urllib/parse.py"},{"path":"/usr/lib/python3.12/urllib/request.py"},{"path":"/usr/lib/python3.12/urllib/response.py"},{"path":"/usr/lib/python3.12/urllib/robotparser.py"},{"path":"/usr/lib/python3.12/venv"},{"path":"/usr/lib/python3.12/venv/__init__.py"},{"path":"/usr/lib/python3.12/venv/__main__.py"},{"path":"/usr/lib/python3.12/venv/scripts"},{"path":"/usr/lib/python3.12/venv/scripts/common"},{"path":"/usr/lib/python3.12/venv/scripts/common/Activate.ps1"},{"path":"/usr/lib/python3.12/venv/scripts/common/activate"},{"path":"/usr/lib/python3.12/venv/scripts/posix"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.csh"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.fish"},{"path":"/usr/lib/python3.12/wsgiref"},{"path":"/usr/lib/python3.12/wsgiref/__init__.py"},{"path":"/usr/lib/python3.12/wsgiref/handlers.py"},{"path":"/usr/lib/python3.12/wsgiref/headers.py"},{"path":"/usr/lib/python3.12/wsgiref/simple_server.py"},{"path":"/usr/lib/python3.12/wsgiref/types.py"},{"path":"/usr/lib/python3.12/wsgiref/util.py"},{"path":"/usr/lib/python3.12/wsgiref/validate.py"},{"path":"/usr/lib/python3.12/xml"},{"path":"/usr/lib/python3.12/xml/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom"},{"path":"/usr/lib/python3.12/xml/dom/NodeFilter.py"},{"path":"/usr/lib/python3.12/xml/dom/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom/domreg.py"},{"path":"/usr/lib/python3.12/xml/dom/expatbuilder.py"},{"path":"/usr/lib/python3.12/xml/dom/minicompat.py"},{"path":"/usr/lib/python3.12/xml/dom/minidom.py"},{"path":"/usr/lib/python3.12/xml/dom/pulldom.py"},{"path":"/usr/lib/python3.12/xml/dom/xmlbuilder.py"},{"path":"/usr/lib/python3.12/xml/etree"},{"path":"/usr/lib/python3.12/xml/etree/ElementInclude.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementPath.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementTree.py"},{"path":"/usr/lib/python3.12/xml/etree/__init__.py"},{"path":"/usr/lib/python3.12/xml/etree/cElementTree.py"},{"path":"/usr/lib/python3.12/xml/parsers"},{"path":"/usr/lib/python3.12/xml/parsers/__init__.py"},{"path":"/usr/lib/python3.12/xml/parsers/expat.py"},{"path":"/usr/lib/python3.12/xml/sax"},{"path":"/usr/lib/python3.12/xml/sax/__init__.py"},{"path":"/usr/lib/python3.12/xml/sax/_exceptions.py"},{"path":"/usr/lib/python3.12/xml/sax/expatreader.py"},{"path":"/usr/lib/python3.12/xml/sax/handler.py"},{"path":"/usr/lib/python3.12/xml/sax/saxutils.py"},{"path":"/usr/lib/python3.12/xml/sax/xmlreader.py"},{"path":"/usr/lib/python3.12/xmlrpc"},{"path":"/usr/lib/python3.12/xmlrpc/__init__.py"},{"path":"/usr/lib/python3.12/xmlrpc/client.py"},{"path":"/usr/lib/python3.12/xmlrpc/server.py"},{"path":"/usr/lib/python3.12/zipfile"},{"path":"/usr/lib/python3.12/zipfile/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/__main__.py"},{"path":"/usr/lib/python3.12/zipfile/_path"},{"path":"/usr/lib/python3.12/zipfile/_path/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/_path/glob.py"},{"path":"/usr/lib/python3.12/zoneinfo"},{"path":"/usr/lib/python3.12/zoneinfo/__init__.py"},{"path":"/usr/lib/python3.12/zoneinfo/_common.py"},{"path":"/usr/lib/python3.12/zoneinfo/_tzpath.py"},{"path":"/usr/lib/python3.12/zoneinfo/_zoneinfo.py"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15367","versionConstraint":"< 3.15.0a6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}},{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15367","versionConstraint":"< 3.15.0a6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.20110500000000003,"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"3669047a8bbbd4c1","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8988-9cw3-xx77","versionConstraint":">=1.26.0,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-8988-9cw3-xx77","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"risk":0.18270999999999998,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77","https://nvd.nist.gov/vuln/detail/CVE-2026-97687","https://github.com/urllib3/urllib3/pull/5093","https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465","https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8988-9cw3-xx77","description":"urllib3: HTTPS proxy TLS configuration may be ignored or overridden"},"relatedVulnerabilities":[{"id":"CVE-2026-97687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"urls":["https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465","https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3","https://github.com/urllib3/urllib3/pull/5093","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97687","description":"urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59848","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59848","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59848","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59848","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59848","date":"2026-10-08","epss":0.00341,"percentile":0.25513}],"risk":0.175615,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59848","https://bugzilla.redhat.com/show_bug.cgi?id=2498181"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59848","description":"A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"3669047a8bbbd4c1","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gh4c-6fx4-qh6g","versionConstraint":">=2.6.2,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-gh4c-6fx4-qh6g","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"risk":0.173145,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g","https://nvd.nist.gov/vuln/detail/CVE-2026-97688","https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gh4c-6fx4-qh6g","description":"urllib3: Chunked Deflate streaming can enter an infinite loop"},"relatedVulnerabilities":[{"id":"CVE-2026-97688","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"urls":["https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97688","description":"urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"8d6f32361002c027","cpes":["cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*"],"name":"nghttp2-libs","purl":"pkg:apk/alpine/nghttp2-libs@1.69.0-r0?arch=x86_64&distro=alpine-3.23.6&upstream=nghttp2","type":"apk","version":"1.69.0-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libnghttp2.so.14"},{"path":"/usr/lib/libnghttp2.so.14.29.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nghttp2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58055","versionConstraint":"<= 1.69.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:nghttp2:nghttp2:1.69.0:*:*:*:*:*:*:*"],"package":{"name":"nghttp2","version":"1.69.0-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58055","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"risk":0.1730575,"urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."},"relatedVulnerabilities":[]},{"artifact":{"id":"5b8a9495e4efe754","cpes":["cpe:2.3:a:busybox:busybox:1.37.0-r30:*:*:*:*:*:*:*"],"name":"busybox","purl":"pkg:apk/alpine/busybox@1.37.0-r30?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"1.37.0-r30","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/busybox"},{"path":"/etc"},{"path":"/etc/securetty"},{"path":"/etc/busybox-paths.d"},{"path":"/etc/busybox-paths.d/busybox"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/acpid"},{"path":"/etc/network"},{"path":"/etc/network/if-down.d"},{"path":"/etc/network/if-post-down.d"},{"path":"/etc/network/if-post-up.d"},{"path":"/etc/network/if-pre-down.d"},{"path":"/etc/network/if-pre-up.d"},{"path":"/etc/network/if-up.d"},{"path":"/etc/network/if-up.d/dad"},{"path":"/etc/udhcpc"},{"path":"/etc/udhcpc/udhcpc.conf"},{"path":"/sbin"},{"path":"/usr"},{"path":"/usr/sbin"},{"path":"/usr/share"},{"path":"/usr/share/udhcpc"},{"path":"/usr/share/udhcpc/default.script"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r30"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"3e88c98a595f91bf","cpes":["cpe:2.3:a:busybox-binsh:busybox-binsh:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:busybox-binsh:busybox_binsh:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox-binsh:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox_binsh:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox-binsh:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox_binsh:1.37.0-r30:*:*:*:*:*:*:*"],"name":"busybox-binsh","purl":"pkg:apk/alpine/busybox-binsh@1.37.0-r30?arch=x86_64&distro=alpine-3.23.6&upstream=busybox","type":"apk","version":"1.37.0-r30","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/sh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r30"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"70e62fc46b7f6a24","cpes":["cpe:2.3:a:ssl-client:ssl-client:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:ssl-client:ssl_client:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl-client:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl_client:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl-client:1.37.0-r30:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl_client:1.37.0-r30:*:*:*:*:*:*:*"],"name":"ssl_client","purl":"pkg:apk/alpine/ssl_client@1.37.0-r30?arch=x86_64&distro=alpine-3.23.6&upstream=busybox","type":"apk","version":"1.37.0-r30","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssl_client"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r30"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69693","versionConstraint":"= 8.0||= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69693","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69693","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69693","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.13832,"urls":["https://github.com/FFmpeg/FFmpeg/commit/8abeb879df66ea8d27ce1735925ced5a30813de4","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0.1"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69693","description":"Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69693","versionConstraint":"= 8.0||= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69693","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69693","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69693","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.13832,"urls":["https://github.com/FFmpeg/FFmpeg/commit/8abeb879df66ea8d27ce1735925ced5a30813de4","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0.1"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69693","description":"Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69693","versionConstraint":"= 8.0||= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69693","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69693","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69693","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.13832,"urls":["https://github.com/FFmpeg/FFmpeg/commit/8abeb879df66ea8d27ce1735925ced5a30813de4","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0.1"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69693","description":"Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69693","versionConstraint":"= 8.0||= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69693","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69693","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69693","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.13832,"urls":["https://github.com/FFmpeg/FFmpeg/commit/8abeb879df66ea8d27ce1735925ced5a30813de4","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0.1"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69693","description":"Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69693","versionConstraint":"= 8.0||= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69693","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69693","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69693","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.13832,"urls":["https://github.com/FFmpeg/FFmpeg/commit/8abeb879df66ea8d27ce1735925ced5a30813de4","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0.1"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69693","description":"Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69693","versionConstraint":"= 8.0||= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69693","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69693","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69693","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.13832,"urls":["https://github.com/FFmpeg/FFmpeg/commit/8abeb879df66ea8d27ce1735925ced5a30813de4","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0.1"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69693","description":"Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69693","versionConstraint":"= 8.0||= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69693","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69693","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69693","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.13832,"urls":["https://github.com/FFmpeg/FFmpeg/commit/8abeb879df66ea8d27ce1735925ced5a30813de4","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0.1"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69693","description":"Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69693","versionConstraint":"= 8.0||= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69693","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69693","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69693","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.13832,"urls":["https://github.com/FFmpeg/FFmpeg/commit/8abeb879df66ea8d27ce1735925ced5a30813de4","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0","https://github.com/FFmpeg/FFmpeg/releases/tag/n8.0.1"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69693","description":"Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"d033f6e836718f4b","cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-project:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:apk/alpine/alsa-lib@1.2.14-r2?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"1.2.14-r2","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/alsa"},{"path":"/etc/alsa/conf.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/aserver"},{"path":"/usr/lib"},{"path":"/usr/lib/libasound.so.2"},{"path":"/usr/lib/libasound.so.2.0.0"},{"path":"/usr/lib/libatopology.so.2"},{"path":"/usr/lib/libatopology.so.2.0.0"},{"path":"/usr/share"},{"path":"/usr/share/alsa"},{"path":"/usr/share/alsa/alsa.conf"},{"path":"/usr/share/alsa/cards"},{"path":"/usr/share/alsa/cards/AACI.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-MODEM.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-SPDMA.conf"},{"path":"/usr/share/alsa/cards/ATIIXP.conf"},{"path":"/usr/share/alsa/cards/AU8810.conf"},{"path":"/usr/share/alsa/cards/AU8820.conf"},{"path":"/usr/share/alsa/cards/AU8830.conf"},{"path":"/usr/share/alsa/cards/Audigy.conf"},{"path":"/usr/share/alsa/cards/Audigy2.conf"},{"path":"/usr/share/alsa/cards/Aureon51.conf"},{"path":"/usr/share/alsa/cards/Aureon71.conf"},{"path":"/usr/share/alsa/cards/CA0106.conf"},{"path":"/usr/share/alsa/cards/CMI8338-SWIEC.conf"},{"path":"/usr/share/alsa/cards/CMI8338.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC6.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC8.conf"},{"path":"/usr/share/alsa/cards/CMI8788.conf"},{"path":"/usr/share/alsa/cards/CS46xx.conf"},{"path":"/usr/share/alsa/cards/EMU10K1.conf"},{"path":"/usr/share/alsa/cards/EMU10K1X.conf"},{"path":"/usr/share/alsa/cards/ENS1370.conf"},{"path":"/usr/share/alsa/cards/ENS1371.conf"},{"path":"/usr/share/alsa/cards/ES1968.conf"},{"path":"/usr/share/alsa/cards/Echo_Echo3G.conf"},{"path":"/usr/share/alsa/cards/FM801.conf"},{"path":"/usr/share/alsa/cards/FWSpeakers.conf"},{"path":"/usr/share/alsa/cards/FireWave.conf"},{"path":"/usr/share/alsa/cards/GUS.conf"},{"path":"/usr/share/alsa/cards/HDA-Intel.conf"},{"path":"/usr/share/alsa/cards/HdmiLpeAudio.conf"},{"path":"/usr/share/alsa/cards/ICE1712.conf"},{"path":"/usr/share/alsa/cards/ICE1724.conf"},{"path":"/usr/share/alsa/cards/ICH-MODEM.conf"},{"path":"/usr/share/alsa/cards/ICH.conf"},{"path":"/usr/share/alsa/cards/ICH4.conf"},{"path":"/usr/share/alsa/cards/Loopback.conf"},{"path":"/usr/share/alsa/cards/Maestro3.conf"},{"path":"/usr/share/alsa/cards/NFORCE.conf"},{"path":"/usr/share/alsa/cards/PC-Speaker.conf"},{"path":"/usr/share/alsa/cards/PMac.conf"},{"path":"/usr/share/alsa/cards/PMacToonie.conf"},{"path":"/usr/share/alsa/cards/PS3.conf"},{"path":"/usr/share/alsa/cards/RME9636.conf"},{"path":"/usr/share/alsa/cards/RME9652.conf"},{"path":"/usr/share/alsa/cards/SB-XFi.conf"},{"path":"/usr/share/alsa/cards/SI7018.conf"},{"path":"/usr/share/alsa/cards/TRID4DWAVENX.conf"},{"path":"/usr/share/alsa/cards/USB-Audio.conf"},{"path":"/usr/share/alsa/cards/VIA686A.conf"},{"path":"/usr/share/alsa/cards/VIA8233.conf"},{"path":"/usr/share/alsa/cards/VIA8233A.conf"},{"path":"/usr/share/alsa/cards/VIA8237.conf"},{"path":"/usr/share/alsa/cards/VX222.conf"},{"path":"/usr/share/alsa/cards/VXPocket.conf"},{"path":"/usr/share/alsa/cards/VXPocket440.conf"},{"path":"/usr/share/alsa/cards/YMF744.conf"},{"path":"/usr/share/alsa/cards/aliases.conf"},{"path":"/usr/share/alsa/cards/pistachio-card.conf"},{"path":"/usr/share/alsa/cards/vc4-hdmi.conf"},{"path":"/usr/share/alsa/ctl"},{"path":"/usr/share/alsa/ctl/default.conf"},{"path":"/usr/share/alsa/pcm"},{"path":"/usr/share/alsa/pcm/center_lfe.conf"},{"path":"/usr/share/alsa/pcm/default.conf"},{"path":"/usr/share/alsa/pcm/dmix.conf"},{"path":"/usr/share/alsa/pcm/dpl.conf"},{"path":"/usr/share/alsa/pcm/dsnoop.conf"},{"path":"/usr/share/alsa/pcm/front.conf"},{"path":"/usr/share/alsa/pcm/hdmi.conf"},{"path":"/usr/share/alsa/pcm/iec958.conf"},{"path":"/usr/share/alsa/pcm/modem.conf"},{"path":"/usr/share/alsa/pcm/rear.conf"},{"path":"/usr/share/alsa/pcm/side.conf"},{"path":"/usr/share/alsa/pcm/surround21.conf"},{"path":"/usr/share/alsa/pcm/surround40.conf"},{"path":"/usr/share/alsa/pcm/surround41.conf"},{"path":"/usr/share/alsa/pcm/surround50.conf"},{"path":"/usr/share/alsa/pcm/surround51.conf"},{"path":"/usr/share/alsa/pcm/surround71.conf"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"alsa-lib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56109","versionConstraint":"< 1.2.16.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14:*:*:*:*:*:*:*"],"package":{"name":"alsa-lib","version":"1.2.14-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56109","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56109","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56109","date":"2026-10-08","epss":0.00186,"percentile":0.07489}],"risk":0.13392,"urls":["https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0","https://github.com/alsa-project/alsa-lib/releases/tag/v1.2.16.1","https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/","https://www.vulncheck.com/advisories/alsa-library-double-free-via-parse-def-in-conf-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56109","description":"The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40962","versionConstraint":"< 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40962","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40962","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40962","date":"2026-10-08","epss":0.00158,"percentile":0.04333}],"risk":0.12916500000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22348"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40962","description":"FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40962","versionConstraint":"< 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40962","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40962","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40962","date":"2026-10-08","epss":0.00158,"percentile":0.04333}],"risk":0.12916500000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22348"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40962","description":"FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40962","versionConstraint":"< 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40962","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40962","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40962","date":"2026-10-08","epss":0.00158,"percentile":0.04333}],"risk":0.12916500000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22348"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40962","description":"FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40962","versionConstraint":"< 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40962","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40962","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40962","date":"2026-10-08","epss":0.00158,"percentile":0.04333}],"risk":0.12916500000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22348"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40962","description":"FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40962","versionConstraint":"< 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40962","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40962","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40962","date":"2026-10-08","epss":0.00158,"percentile":0.04333}],"risk":0.12916500000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22348"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40962","description":"FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40962","versionConstraint":"< 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40962","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40962","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40962","date":"2026-10-08","epss":0.00158,"percentile":0.04333}],"risk":0.12916500000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22348"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40962","description":"FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40962","versionConstraint":"< 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40962","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40962","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40962","date":"2026-10-08","epss":0.00158,"percentile":0.04333}],"risk":0.12916500000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22348"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40962","description":"FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40962","versionConstraint":"< 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40962","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40962","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40962","date":"2026-10-08","epss":0.00158,"percentile":0.04333}],"risk":0.12916500000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22348"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40962","description":"FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"09c24a4342b1cfdb","cpes":["cpe:2.3:a:python-software-foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.12.15-r0:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:apk/alpine/python3@3.12.15-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"3.12.15-r0","language":"","licenses":["PSF-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/2to3"},{"path":"/usr/bin/2to3-3.12"},{"path":"/usr/bin/pydoc3"},{"path":"/usr/bin/pydoc3.12"},{"path":"/usr/bin/python"},{"path":"/usr/bin/python3"},{"path":"/usr/bin/python3.12"},{"path":"/usr/include"},{"path":"/usr/include/python3.12"},{"path":"/usr/include/python3.12/pyconfig.h"},{"path":"/usr/lib"},{"path":"/usr/lib/libpython3.12.so.1.0"},{"path":"/usr/lib/libpython3.so"},{"path":"/usr/lib/python3.12"},{"path":"/usr/lib/python3.12/EXTERNALLY-MANAGED"},{"path":"/usr/lib/python3.12/LICENSE.txt"},{"path":"/usr/lib/python3.12/__future__.py"},{"path":"/usr/lib/python3.12/__hello__.py"},{"path":"/usr/lib/python3.12/_aix_support.py"},{"path":"/usr/lib/python3.12/_collections_abc.py"},{"path":"/usr/lib/python3.12/_compat_pickle.py"},{"path":"/usr/lib/python3.12/_compression.py"},{"path":"/usr/lib/python3.12/_markupbase.py"},{"path":"/usr/lib/python3.12/_osx_support.py"},{"path":"/usr/lib/python3.12/_py_abc.py"},{"path":"/usr/lib/python3.12/_pydatetime.py"},{"path":"/usr/lib/python3.12/_pydecimal.py"},{"path":"/usr/lib/python3.12/_pyio.py"},{"path":"/usr/lib/python3.12/_pylong.py"},{"path":"/usr/lib/python3.12/_sitebuiltins.py"},{"path":"/usr/lib/python3.12/_strptime.py"},{"path":"/usr/lib/python3.12/_sysconfigdata__linux_x86_64-linux-musl.py"},{"path":"/usr/lib/python3.12/_threading_local.py"},{"path":"/usr/lib/python3.12/_weakrefset.py"},{"path":"/usr/lib/python3.12/abc.py"},{"path":"/usr/lib/python3.12/aifc.py"},{"path":"/usr/lib/python3.12/antigravity.py"},{"path":"/usr/lib/python3.12/argparse.py"},{"path":"/usr/lib/python3.12/ast.py"},{"path":"/usr/lib/python3.12/base64.py"},{"path":"/usr/lib/python3.12/bdb.py"},{"path":"/usr/lib/python3.12/bisect.py"},{"path":"/usr/lib/python3.12/bz2.py"},{"path":"/usr/lib/python3.12/cProfile.py"},{"path":"/usr/lib/python3.12/calendar.py"},{"path":"/usr/lib/python3.12/cgi.py"},{"path":"/usr/lib/python3.12/cgitb.py"},{"path":"/usr/lib/python3.12/chunk.py"},{"path":"/usr/lib/python3.12/cmd.py"},{"path":"/usr/lib/python3.12/code.py"},{"path":"/usr/lib/python3.12/codecs.py"},{"path":"/usr/lib/python3.12/codeop.py"},{"path":"/usr/lib/python3.12/colorsys.py"},{"path":"/usr/lib/python3.12/compileall.py"},{"path":"/usr/lib/python3.12/configparser.py"},{"path":"/usr/lib/python3.12/contextlib.py"},{"path":"/usr/lib/python3.12/contextvars.py"},{"path":"/usr/lib/python3.12/copy.py"},{"path":"/usr/lib/python3.12/copyreg.py"},{"path":"/usr/lib/python3.12/crypt.py"},{"path":"/usr/lib/python3.12/csv.py"},{"path":"/usr/lib/python3.12/dataclasses.py"},{"path":"/usr/lib/python3.12/datetime.py"},{"path":"/usr/lib/python3.12/decimal.py"},{"path":"/usr/lib/python3.12/difflib.py"},{"path":"/usr/lib/python3.12/dis.py"},{"path":"/usr/lib/python3.12/doctest.py"},{"path":"/usr/lib/python3.12/enum.py"},{"path":"/usr/lib/python3.12/filecmp.py"},{"path":"/usr/lib/python3.12/fileinput.py"},{"path":"/usr/lib/python3.12/fnmatch.py"},{"path":"/usr/lib/python3.12/fractions.py"},{"path":"/usr/lib/python3.12/ftplib.py"},{"path":"/usr/lib/python3.12/functools.py"},{"path":"/usr/lib/python3.12/genericpath.py"},{"path":"/usr/lib/python3.12/getopt.py"},{"path":"/usr/lib/python3.12/getpass.py"},{"path":"/usr/lib/python3.12/gettext.py"},{"path":"/usr/lib/python3.12/glob.py"},{"path":"/usr/lib/python3.12/graphlib.py"},{"path":"/usr/lib/python3.12/gzip.py"},{"path":"/usr/lib/python3.12/hashlib.py"},{"path":"/usr/lib/python3.12/heapq.py"},{"path":"/usr/lib/python3.12/hmac.py"},{"path":"/usr/lib/python3.12/imaplib.py"},{"path":"/usr/lib/python3.12/imghdr.py"},{"path":"/usr/lib/python3.12/inspect.py"},{"path":"/usr/lib/python3.12/io.py"},{"path":"/usr/lib/python3.12/ipaddress.py"},{"path":"/usr/lib/python3.12/keyword.py"},{"path":"/usr/lib/python3.12/linecache.py"},{"path":"/usr/lib/python3.12/locale.py"},{"path":"/usr/lib/python3.12/lzma.py"},{"path":"/usr/lib/python3.12/mailbox.py"},{"path":"/usr/lib/python3.12/mailcap.py"},{"path":"/usr/lib/python3.12/mimetypes.py"},{"path":"/usr/lib/python3.12/modulefinder.py"},{"path":"/usr/lib/python3.12/netrc.py"},{"path":"/usr/lib/python3.12/nntplib.py"},{"path":"/usr/lib/python3.12/ntpath.py"},{"path":"/usr/lib/python3.12/nturl2path.py"},{"path":"/usr/lib/python3.12/numbers.py"},{"path":"/usr/lib/python3.12/opcode.py"},{"path":"/usr/lib/python3.12/operator.py"},{"path":"/usr/lib/python3.12/optparse.py"},{"path":"/usr/lib/python3.12/os.py"},{"path":"/usr/lib/python3.12/pathlib.py"},{"path":"/usr/lib/python3.12/pdb.py"},{"path":"/usr/lib/python3.12/pickle.py"},{"path":"/usr/lib/python3.12/pickletools.py"},{"path":"/usr/lib/python3.12/pipes.py"},{"path":"/usr/lib/python3.12/pkgutil.py"},{"path":"/usr/lib/python3.12/platform.py"},{"path":"/usr/lib/python3.12/plistlib.py"},{"path":"/usr/lib/python3.12/poplib.py"},{"path":"/usr/lib/python3.12/posixpath.py"},{"path":"/usr/lib/python3.12/pprint.py"},{"path":"/usr/lib/python3.12/profile.py"},{"path":"/usr/lib/python3.12/pstats.py"},{"path":"/usr/lib/python3.12/pty.py"},{"path":"/usr/lib/python3.12/py_compile.py"},{"path":"/usr/lib/python3.12/pyclbr.py"},{"path":"/usr/lib/python3.12/pydoc.py"},{"path":"/usr/lib/python3.12/queue.py"},{"path":"/usr/lib/python3.12/quopri.py"},{"path":"/usr/lib/python3.12/random.py"},{"path":"/usr/lib/python3.12/reprlib.py"},{"path":"/usr/lib/python3.12/rlcompleter.py"},{"path":"/usr/lib/python3.12/runpy.py"},{"path":"/usr/lib/python3.12/sched.py"},{"path":"/usr/lib/python3.12/secrets.py"},{"path":"/usr/lib/python3.12/selectors.py"},{"path":"/usr/lib/python3.12/shelve.py"},{"path":"/usr/lib/python3.12/shlex.py"},{"path":"/usr/lib/python3.12/shutil.py"},{"path":"/usr/lib/python3.12/signal.py"},{"path":"/usr/lib/python3.12/site.py"},{"path":"/usr/lib/python3.12/smtplib.py"},{"path":"/usr/lib/python3.12/sndhdr.py"},{"path":"/usr/lib/python3.12/socket.py"},{"path":"/usr/lib/python3.12/socketserver.py"},{"path":"/usr/lib/python3.12/sre_compile.py"},{"path":"/usr/lib/python3.12/sre_constants.py"},{"path":"/usr/lib/python3.12/sre_parse.py"},{"path":"/usr/lib/python3.12/ssl.py"},{"path":"/usr/lib/python3.12/stat.py"},{"path":"/usr/lib/python3.12/statistics.py"},{"path":"/usr/lib/python3.12/string.py"},{"path":"/usr/lib/python3.12/stringprep.py"},{"path":"/usr/lib/python3.12/struct.py"},{"path":"/usr/lib/python3.12/subprocess.py"},{"path":"/usr/lib/python3.12/sunau.py"},{"path":"/usr/lib/python3.12/symtable.py"},{"path":"/usr/lib/python3.12/sysconfig.py"},{"path":"/usr/lib/python3.12/tabnanny.py"},{"path":"/usr/lib/python3.12/tarfile.py"},{"path":"/usr/lib/python3.12/telnetlib.py"},{"path":"/usr/lib/python3.12/tempfile.py"},{"path":"/usr/lib/python3.12/textwrap.py"},{"path":"/usr/lib/python3.12/this.py"},{"path":"/usr/lib/python3.12/threading.py"},{"path":"/usr/lib/python3.12/timeit.py"},{"path":"/usr/lib/python3.12/token.py"},{"path":"/usr/lib/python3.12/tokenize.py"},{"path":"/usr/lib/python3.12/trace.py"},{"path":"/usr/lib/python3.12/traceback.py"},{"path":"/usr/lib/python3.12/tracemalloc.py"},{"path":"/usr/lib/python3.12/tty.py"},{"path":"/usr/lib/python3.12/turtle.py"},{"path":"/usr/lib/python3.12/types.py"},{"path":"/usr/lib/python3.12/typing.py"},{"path":"/usr/lib/python3.12/uu.py"},{"path":"/usr/lib/python3.12/uuid.py"},{"path":"/usr/lib/python3.12/warnings.py"},{"path":"/usr/lib/python3.12/wave.py"},{"path":"/usr/lib/python3.12/weakref.py"},{"path":"/usr/lib/python3.12/webbrowser.py"},{"path":"/usr/lib/python3.12/xdrlib.py"},{"path":"/usr/lib/python3.12/zipapp.py"},{"path":"/usr/lib/python3.12/zipimport.py"},{"path":"/usr/lib/python3.12/__phello__"},{"path":"/usr/lib/python3.12/__phello__/__init__.py"},{"path":"/usr/lib/python3.12/__phello__/spam.py"},{"path":"/usr/lib/python3.12/asyncio"},{"path":"/usr/lib/python3.12/asyncio/__init__.py"},{"path":"/usr/lib/python3.12/asyncio/__main__.py"},{"path":"/usr/lib/python3.12/asyncio/base_events.py"},{"path":"/usr/lib/python3.12/asyncio/base_futures.py"},{"path":"/usr/lib/python3.12/asyncio/base_subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/base_tasks.py"},{"path":"/usr/lib/python3.12/asyncio/constants.py"},{"path":"/usr/lib/python3.12/asyncio/coroutines.py"},{"path":"/usr/lib/python3.12/asyncio/events.py"},{"path":"/usr/lib/python3.12/asyncio/exceptions.py"},{"path":"/usr/lib/python3.12/asyncio/format_helpers.py"},{"path":"/usr/lib/python3.12/asyncio/futures.py"},{"path":"/usr/lib/python3.12/asyncio/locks.py"},{"path":"/usr/lib/python3.12/asyncio/log.py"},{"path":"/usr/lib/python3.12/asyncio/mixins.py"},{"path":"/usr/lib/python3.12/asyncio/proactor_events.py"},{"path":"/usr/lib/python3.12/asyncio/protocols.py"},{"path":"/usr/lib/python3.12/asyncio/queues.py"},{"path":"/usr/lib/python3.12/asyncio/runners.py"},{"path":"/usr/lib/python3.12/asyncio/selector_events.py"},{"path":"/usr/lib/python3.12/asyncio/sslproto.py"},{"path":"/usr/lib/python3.12/asyncio/staggered.py"},{"path":"/usr/lib/python3.12/asyncio/streams.py"},{"path":"/usr/lib/python3.12/asyncio/subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/taskgroups.py"},{"path":"/usr/lib/python3.12/asyncio/tasks.py"},{"path":"/usr/lib/python3.12/asyncio/threads.py"},{"path":"/usr/lib/python3.12/asyncio/timeouts.py"},{"path":"/usr/lib/python3.12/asyncio/transports.py"},{"path":"/usr/lib/python3.12/asyncio/trsock.py"},{"path":"/usr/lib/python3.12/asyncio/unix_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_utils.py"},{"path":"/usr/lib/python3.12/collections"},{"path":"/usr/lib/python3.12/collections/__init__.py"},{"path":"/usr/lib/python3.12/collections/abc.py"},{"path":"/usr/lib/python3.12/concurrent"},{"path":"/usr/lib/python3.12/concurrent/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures"},{"path":"/usr/lib/python3.12/concurrent/futures/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures/_base.py"},{"path":"/usr/lib/python3.12/concurrent/futures/process.py"},{"path":"/usr/lib/python3.12/concurrent/futures/thread.py"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Makefile"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.bootstrap"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.local"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.stdlib"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/config.c.in"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/install-sh"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/makesetup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/python-config.py"},{"path":"/usr/lib/python3.12/ctypes"},{"path":"/usr/lib/python3.12/ctypes/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/_aix.py"},{"path":"/usr/lib/python3.12/ctypes/_endian.py"},{"path":"/usr/lib/python3.12/ctypes/util.py"},{"path":"/usr/lib/python3.12/ctypes/wintypes.py"},{"path":"/usr/lib/python3.12/ctypes/macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/README.ctypes"},{"path":"/usr/lib/python3.12/ctypes/macholib/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dyld.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dylib.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib.bat"},{"path":"/usr/lib/python3.12/ctypes/macholib/framework.py"},{"path":"/usr/lib/python3.12/curses"},{"path":"/usr/lib/python3.12/curses/__init__.py"},{"path":"/usr/lib/python3.12/curses/ascii.py"},{"path":"/usr/lib/python3.12/curses/has_key.py"},{"path":"/usr/lib/python3.12/curses/panel.py"},{"path":"/usr/lib/python3.12/curses/textpad.py"},{"path":"/usr/lib/python3.12/dbm"},{"path":"/usr/lib/python3.12/dbm/__init__.py"},{"path":"/usr/lib/python3.12/dbm/dumb.py"},{"path":"/usr/lib/python3.12/dbm/gnu.py"},{"path":"/usr/lib/python3.12/dbm/ndbm.py"},{"path":"/usr/lib/python3.12/email"},{"path":"/usr/lib/python3.12/email/__init__.py"},{"path":"/usr/lib/python3.12/email/_encoded_words.py"},{"path":"/usr/lib/python3.12/email/_header_value_parser.py"},{"path":"/usr/lib/python3.12/email/_parseaddr.py"},{"path":"/usr/lib/python3.12/email/_policybase.py"},{"path":"/usr/lib/python3.12/email/architecture.rst"},{"path":"/usr/lib/python3.12/email/base64mime.py"},{"path":"/usr/lib/python3.12/email/charset.py"},{"path":"/usr/lib/python3.12/email/contentmanager.py"},{"path":"/usr/lib/python3.12/email/encoders.py"},{"path":"/usr/lib/python3.12/email/errors.py"},{"path":"/usr/lib/python3.12/email/feedparser.py"},{"path":"/usr/lib/python3.12/email/generator.py"},{"path":"/usr/lib/python3.12/email/header.py"},{"path":"/usr/lib/python3.12/email/headerregistry.py"},{"path":"/usr/lib/python3.12/email/iterators.py"},{"path":"/usr/lib/python3.12/email/message.py"},{"path":"/usr/lib/python3.12/email/parser.py"},{"path":"/usr/lib/python3.12/email/policy.py"},{"path":"/usr/lib/python3.12/email/quoprimime.py"},{"path":"/usr/lib/python3.12/email/utils.py"},{"path":"/usr/lib/python3.12/email/mime"},{"path":"/usr/lib/python3.12/email/mime/__init__.py"},{"path":"/usr/lib/python3.12/email/mime/application.py"},{"path":"/usr/lib/python3.12/email/mime/audio.py"},{"path":"/usr/lib/python3.12/email/mime/base.py"},{"path":"/usr/lib/python3.12/email/mime/image.py"},{"path":"/usr/lib/python3.12/email/mime/message.py"},{"path":"/usr/lib/python3.12/email/mime/multipart.py"},{"path":"/usr/lib/python3.12/email/mime/nonmultipart.py"},{"path":"/usr/lib/python3.12/email/mime/text.py"},{"path":"/usr/lib/python3.12/encodings"},{"path":"/usr/lib/python3.12/encodings/__init__.py"},{"path":"/usr/lib/python3.12/encodings/aliases.py"},{"path":"/usr/lib/python3.12/encodings/ascii.py"},{"path":"/usr/lib/python3.12/encodings/base64_codec.py"},{"path":"/usr/lib/python3.12/encodings/big5.py"},{"path":"/usr/lib/python3.12/encodings/big5hkscs.py"},{"path":"/usr/lib/python3.12/encodings/bz2_codec.py"},{"path":"/usr/lib/python3.12/encodings/charmap.py"},{"path":"/usr/lib/python3.12/encodings/cp037.py"},{"path":"/usr/lib/python3.12/encodings/cp1006.py"},{"path":"/usr/lib/python3.12/encodings/cp1026.py"},{"path":"/usr/lib/python3.12/encodings/cp1125.py"},{"path":"/usr/lib/python3.12/encodings/cp1140.py"},{"path":"/usr/lib/python3.12/encodings/cp1250.py"},{"path":"/usr/lib/python3.12/encodings/cp1251.py"},{"path":"/usr/lib/python3.12/encodings/cp1252.py"},{"path":"/usr/lib/python3.12/encodings/cp1253.py"},{"path":"/usr/lib/python3.12/encodings/cp1254.py"},{"path":"/usr/lib/python3.12/encodings/cp1255.py"},{"path":"/usr/lib/python3.12/encodings/cp1256.py"},{"path":"/usr/lib/python3.12/encodings/cp1257.py"},{"path":"/usr/lib/python3.12/encodings/cp1258.py"},{"path":"/usr/lib/python3.12/encodings/cp273.py"},{"path":"/usr/lib/python3.12/encodings/cp424.py"},{"path":"/usr/lib/python3.12/encodings/cp437.py"},{"path":"/usr/lib/python3.12/encodings/cp500.py"},{"path":"/usr/lib/python3.12/encodings/cp720.py"},{"path":"/usr/lib/python3.12/encodings/cp737.py"},{"path":"/usr/lib/python3.12/encodings/cp775.py"},{"path":"/usr/lib/python3.12/encodings/cp850.py"},{"path":"/usr/lib/python3.12/encodings/cp852.py"},{"path":"/usr/lib/python3.12/encodings/cp855.py"},{"path":"/usr/lib/python3.12/encodings/cp856.py"},{"path":"/usr/lib/python3.12/encodings/cp857.py"},{"path":"/usr/lib/python3.12/encodings/cp858.py"},{"path":"/usr/lib/python3.12/encodings/cp860.py"},{"path":"/usr/lib/python3.12/encodings/cp861.py"},{"path":"/usr/lib/python3.12/encodings/cp862.py"},{"path":"/usr/lib/python3.12/encodings/cp863.py"},{"path":"/usr/lib/python3.12/encodings/cp864.py"},{"path":"/usr/lib/python3.12/encodings/cp865.py"},{"path":"/usr/lib/python3.12/encodings/cp866.py"},{"path":"/usr/lib/python3.12/encodings/cp869.py"},{"path":"/usr/lib/python3.12/encodings/cp874.py"},{"path":"/usr/lib/python3.12/encodings/cp875.py"},{"path":"/usr/lib/python3.12/encodings/cp932.py"},{"path":"/usr/lib/python3.12/encodings/cp949.py"},{"path":"/usr/lib/python3.12/encodings/cp950.py"},{"path":"/usr/lib/python3.12/encodings/euc_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/euc_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/euc_jp.py"},{"path":"/usr/lib/python3.12/encodings/euc_kr.py"},{"path":"/usr/lib/python3.12/encodings/gb18030.py"},{"path":"/usr/lib/python3.12/encodings/gb2312.py"},{"path":"/usr/lib/python3.12/encodings/gbk.py"},{"path":"/usr/lib/python3.12/encodings/hex_codec.py"},{"path":"/usr/lib/python3.12/encodings/hp_roman8.py"},{"path":"/usr/lib/python3.12/encodings/hz.py"},{"path":"/usr/lib/python3.12/encodings/idna.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_1.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2004.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_3.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_ext.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_kr.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_1.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_10.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_11.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_13.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_14.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_15.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_16.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_2.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_3.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_4.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_5.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_6.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_7.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_8.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_9.py"},{"path":"/usr/lib/python3.12/encodings/johab.py"},{"path":"/usr/lib/python3.12/encodings/koi8_r.py"},{"path":"/usr/lib/python3.12/encodings/koi8_t.py"},{"path":"/usr/lib/python3.12/encodings/koi8_u.py"},{"path":"/usr/lib/python3.12/encodings/kz1048.py"},{"path":"/usr/lib/python3.12/encodings/latin_1.py"},{"path":"/usr/lib/python3.12/encodings/mac_arabic.py"},{"path":"/usr/lib/python3.12/encodings/mac_croatian.py"},{"path":"/usr/lib/python3.12/encodings/mac_cyrillic.py"},{"path":"/usr/lib/python3.12/encodings/mac_farsi.py"},{"path":"/usr/lib/python3.12/encodings/mac_greek.py"},{"path":"/usr/lib/python3.12/encodings/mac_iceland.py"},{"path":"/usr/lib/python3.12/encodings/mac_latin2.py"},{"path":"/usr/lib/python3.12/encodings/mac_roman.py"},{"path":"/usr/lib/python3.12/encodings/mac_romanian.py"},{"path":"/usr/lib/python3.12/encodings/mac_turkish.py"},{"path":"/usr/lib/python3.12/encodings/mbcs.py"},{"path":"/usr/lib/python3.12/encodings/oem.py"},{"path":"/usr/lib/python3.12/encodings/palmos.py"},{"path":"/usr/lib/python3.12/encodings/ptcp154.py"},{"path":"/usr/lib/python3.12/encodings/punycode.py"},{"path":"/usr/lib/python3.12/encodings/quopri_codec.py"},{"path":"/usr/lib/python3.12/encodings/raw_unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/rot_13.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/shift_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/tis_620.py"},{"path":"/usr/lib/python3.12/encodings/undefined.py"},{"path":"/usr/lib/python3.12/encodings/unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/utf_16.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_32.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_7.py"},{"path":"/usr/lib/python3.12/encodings/utf_8.py"},{"path":"/usr/lib/python3.12/encodings/utf_8_sig.py"},{"path":"/usr/lib/python3.12/encodings/uu_codec.py"},{"path":"/usr/lib/python3.12/encodings/zlib_codec.py"},{"path":"/usr/lib/python3.12/ensurepip"},{"path":"/usr/lib/python3.12/ensurepip/__init__.py"},{"path":"/usr/lib/python3.12/ensurepip/__main__.py"},{"path":"/usr/lib/python3.12/ensurepip/_uninstall.py"},{"path":"/usr/lib/python3.12/ensurepip/_bundled"},{"path":"/usr/lib/python3.12/ensurepip/_bundled/pip-25.0.1-py3-none-any.whl"},{"path":"/usr/lib/python3.12/html"},{"path":"/usr/lib/python3.12/html/__init__.py"},{"path":"/usr/lib/python3.12/html/entities.py"},{"path":"/usr/lib/python3.12/html/parser.py"},{"path":"/usr/lib/python3.12/http"},{"path":"/usr/lib/python3.12/http/__init__.py"},{"path":"/usr/lib/python3.12/http/client.py"},{"path":"/usr/lib/python3.12/http/cookiejar.py"},{"path":"/usr/lib/python3.12/http/cookies.py"},{"path":"/usr/lib/python3.12/http/server.py"},{"path":"/usr/lib/python3.12/importlib"},{"path":"/usr/lib/python3.12/importlib/__init__.py"},{"path":"/usr/lib/python3.12/importlib/_abc.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap_external.py"},{"path":"/usr/lib/python3.12/importlib/abc.py"},{"path":"/usr/lib/python3.12/importlib/machinery.py"},{"path":"/usr/lib/python3.12/importlib/readers.py"},{"path":"/usr/lib/python3.12/importlib/simple.py"},{"path":"/usr/lib/python3.12/importlib/util.py"},{"path":"/usr/lib/python3.12/importlib/metadata"},{"path":"/usr/lib/python3.12/importlib/metadata/__init__.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_collections.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_functools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_meta.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_text.py"},{"path":"/usr/lib/python3.12/importlib/resources"},{"path":"/usr/lib/python3.12/importlib/resources/__init__.py"},{"path":"/usr/lib/python3.12/importlib/resources/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/resources/_common.py"},{"path":"/usr/lib/python3.12/importlib/resources/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/resources/_legacy.py"},{"path":"/usr/lib/python3.12/importlib/resources/abc.py"},{"path":"/usr/lib/python3.12/importlib/resources/readers.py"},{"path":"/usr/lib/python3.12/importlib/resources/simple.py"},{"path":"/usr/lib/python3.12/json"},{"path":"/usr/lib/python3.12/json/__init__.py"},{"path":"/usr/lib/python3.12/json/decoder.py"},{"path":"/usr/lib/python3.12/json/encoder.py"},{"path":"/usr/lib/python3.12/json/scanner.py"},{"path":"/usr/lib/python3.12/json/tool.py"},{"path":"/usr/lib/python3.12/lib-dynload"},{"path":"/usr/lib/python3.12/lib-dynload/_asyncio.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bisect.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_blake2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bz2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_cn.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_hk.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_iso2022.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_jp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_kr.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_tw.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_contextvars.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_crypt.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_csv.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes_test.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses_panel.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_datetime.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_dbm.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_decimal.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_elementtree.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_hashlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_heapq.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_json.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lsprof.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lzma.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_md5.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multibytecodec.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multiprocessing.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_opcode.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_pickle.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixshmem.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixsubprocess.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_queue.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_random.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha1.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_socket.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sqlite3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ssl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_statistics.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_struct.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testbuffer.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testclinic.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testimportmultiple.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testinternalcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testmultiphase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testsinglephase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxinterpchannels.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxsubinterpreters.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxtestfuzz.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_zoneinfo.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/array.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/audioop.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/binascii.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/cmath.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/fcntl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/grp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/math.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/mmap.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/ossaudiodev.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/pyexpat.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/readline.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/resource.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/select.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/spwd.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/syslog.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/termios.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/unicodedata.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited_35.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxsubtype.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/zlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib2to3"},{"path":"/usr/lib/python3.12/lib2to3/Grammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/Grammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/__main__.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_matcher.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_utils.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_base.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_util.py"},{"path":"/usr/lib/python3.12/lib2to3/main.py"},{"path":"/usr/lib/python3.12/lib2to3/patcomp.py"},{"path":"/usr/lib/python3.12/lib2to3/pygram.py"},{"path":"/usr/lib/python3.12/lib2to3/pytree.py"},{"path":"/usr/lib/python3.12/lib2to3/refactor.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes"},{"path":"/usr/lib/python3.12/lib2to3/fixes/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_apply.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_asserts.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_basestring.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_buffer.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_dict.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_except.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exec.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_execfile.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exitfunc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_filter.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_funcattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_future.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_getcwdu.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_has_key.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_idioms.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_import.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports2.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_intern.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_isinstance.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_long.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_map.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_metaclass.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_methodattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ne.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_next.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_nonzero.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_numliterals.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_operator.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_paren.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_print.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raise.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raw_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reduce.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reload.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_renames.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_repr.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_set_literal.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_standarderror.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_sys_exc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_throw.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_tuple_params.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_types.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_unicode.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_urllib.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ws_comma.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xrange.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xreadlines.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_zip.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/conv.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/driver.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/grammar.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/literals.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/parse.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/pgen.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/token.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/tokenize.py"},{"path":"/usr/lib/python3.12/logging"},{"path":"/usr/lib/python3.12/logging/__init__.py"},{"path":"/usr/lib/python3.12/logging/config.py"},{"path":"/usr/lib/python3.12/logging/handlers.py"},{"path":"/usr/lib/python3.12/multiprocessing"},{"path":"/usr/lib/python3.12/multiprocessing/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/connection.py"},{"path":"/usr/lib/python3.12/multiprocessing/context.py"},{"path":"/usr/lib/python3.12/multiprocessing/forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/heap.py"},{"path":"/usr/lib/python3.12/multiprocessing/managers.py"},{"path":"/usr/lib/python3.12/multiprocessing/pool.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_fork.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_posix.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_win32.py"},{"path":"/usr/lib/python3.12/multiprocessing/process.py"},{"path":"/usr/lib/python3.12/multiprocessing/queues.py"},{"path":"/usr/lib/python3.12/multiprocessing/reduction.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_sharer.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_tracker.py"},{"path":"/usr/lib/python3.12/multiprocessing/shared_memory.py"},{"path":"/usr/lib/python3.12/multiprocessing/sharedctypes.py"},{"path":"/usr/lib/python3.12/multiprocessing/spawn.py"},{"path":"/usr/lib/python3.12/multiprocessing/synchronize.py"},{"path":"/usr/lib/python3.12/multiprocessing/util.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/connection.py"},{"path":"/usr/lib/python3.12/pydoc_data"},{"path":"/usr/lib/python3.12/pydoc_data/__init__.py"},{"path":"/usr/lib/python3.12/pydoc_data/_pydoc.css"},{"path":"/usr/lib/python3.12/pydoc_data/topics.py"},{"path":"/usr/lib/python3.12/re"},{"path":"/usr/lib/python3.12/re/__init__.py"},{"path":"/usr/lib/python3.12/re/_casefix.py"},{"path":"/usr/lib/python3.12/re/_compiler.py"},{"path":"/usr/lib/python3.12/re/_constants.py"},{"path":"/usr/lib/python3.12/re/_parser.py"},{"path":"/usr/lib/python3.12/site-packages"},{"path":"/usr/lib/python3.12/site-packages/README.txt"},{"path":"/usr/lib/python3.12/sqlite3"},{"path":"/usr/lib/python3.12/sqlite3/__init__.py"},{"path":"/usr/lib/python3.12/sqlite3/__main__.py"},{"path":"/usr/lib/python3.12/sqlite3/dbapi2.py"},{"path":"/usr/lib/python3.12/sqlite3/dump.py"},{"path":"/usr/lib/python3.12/tomllib"},{"path":"/usr/lib/python3.12/tomllib/__init__.py"},{"path":"/usr/lib/python3.12/tomllib/_parser.py"},{"path":"/usr/lib/python3.12/tomllib/_re.py"},{"path":"/usr/lib/python3.12/tomllib/_types.py"},{"path":"/usr/lib/python3.12/turtledemo"},{"path":"/usr/lib/python3.12/turtledemo/__init__.py"},{"path":"/usr/lib/python3.12/turtledemo/__main__.py"},{"path":"/usr/lib/python3.12/turtledemo/bytedesign.py"},{"path":"/usr/lib/python3.12/turtledemo/chaos.py"},{"path":"/usr/lib/python3.12/turtledemo/clock.py"},{"path":"/usr/lib/python3.12/turtledemo/colormixer.py"},{"path":"/usr/lib/python3.12/turtledemo/forest.py"},{"path":"/usr/lib/python3.12/turtledemo/fractalcurves.py"},{"path":"/usr/lib/python3.12/turtledemo/lindenmayer.py"},{"path":"/usr/lib/python3.12/turtledemo/minimal_hanoi.py"},{"path":"/usr/lib/python3.12/turtledemo/nim.py"},{"path":"/usr/lib/python3.12/turtledemo/paint.py"},{"path":"/usr/lib/python3.12/turtledemo/peace.py"},{"path":"/usr/lib/python3.12/turtledemo/penrose.py"},{"path":"/usr/lib/python3.12/turtledemo/planet_and_moon.py"},{"path":"/usr/lib/python3.12/turtledemo/rosette.py"},{"path":"/usr/lib/python3.12/turtledemo/round_dance.py"},{"path":"/usr/lib/python3.12/turtledemo/sorting_animate.py"},{"path":"/usr/lib/python3.12/turtledemo/tree.py"},{"path":"/usr/lib/python3.12/turtledemo/turtle.cfg"},{"path":"/usr/lib/python3.12/turtledemo/two_canvases.py"},{"path":"/usr/lib/python3.12/turtledemo/yinyang.py"},{"path":"/usr/lib/python3.12/unittest"},{"path":"/usr/lib/python3.12/unittest/__init__.py"},{"path":"/usr/lib/python3.12/unittest/__main__.py"},{"path":"/usr/lib/python3.12/unittest/_log.py"},{"path":"/usr/lib/python3.12/unittest/async_case.py"},{"path":"/usr/lib/python3.12/unittest/case.py"},{"path":"/usr/lib/python3.12/unittest/loader.py"},{"path":"/usr/lib/python3.12/unittest/main.py"},{"path":"/usr/lib/python3.12/unittest/mock.py"},{"path":"/usr/lib/python3.12/unittest/result.py"},{"path":"/usr/lib/python3.12/unittest/runner.py"},{"path":"/usr/lib/python3.12/unittest/signals.py"},{"path":"/usr/lib/python3.12/unittest/suite.py"},{"path":"/usr/lib/python3.12/unittest/util.py"},{"path":"/usr/lib/python3.12/urllib"},{"path":"/usr/lib/python3.12/urllib/__init__.py"},{"path":"/usr/lib/python3.12/urllib/error.py"},{"path":"/usr/lib/python3.12/urllib/parse.py"},{"path":"/usr/lib/python3.12/urllib/request.py"},{"path":"/usr/lib/python3.12/urllib/response.py"},{"path":"/usr/lib/python3.12/urllib/robotparser.py"},{"path":"/usr/lib/python3.12/venv"},{"path":"/usr/lib/python3.12/venv/__init__.py"},{"path":"/usr/lib/python3.12/venv/__main__.py"},{"path":"/usr/lib/python3.12/venv/scripts"},{"path":"/usr/lib/python3.12/venv/scripts/common"},{"path":"/usr/lib/python3.12/venv/scripts/common/Activate.ps1"},{"path":"/usr/lib/python3.12/venv/scripts/common/activate"},{"path":"/usr/lib/python3.12/venv/scripts/posix"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.csh"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.fish"},{"path":"/usr/lib/python3.12/wsgiref"},{"path":"/usr/lib/python3.12/wsgiref/__init__.py"},{"path":"/usr/lib/python3.12/wsgiref/handlers.py"},{"path":"/usr/lib/python3.12/wsgiref/headers.py"},{"path":"/usr/lib/python3.12/wsgiref/simple_server.py"},{"path":"/usr/lib/python3.12/wsgiref/types.py"},{"path":"/usr/lib/python3.12/wsgiref/util.py"},{"path":"/usr/lib/python3.12/wsgiref/validate.py"},{"path":"/usr/lib/python3.12/xml"},{"path":"/usr/lib/python3.12/xml/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom"},{"path":"/usr/lib/python3.12/xml/dom/NodeFilter.py"},{"path":"/usr/lib/python3.12/xml/dom/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom/domreg.py"},{"path":"/usr/lib/python3.12/xml/dom/expatbuilder.py"},{"path":"/usr/lib/python3.12/xml/dom/minicompat.py"},{"path":"/usr/lib/python3.12/xml/dom/minidom.py"},{"path":"/usr/lib/python3.12/xml/dom/pulldom.py"},{"path":"/usr/lib/python3.12/xml/dom/xmlbuilder.py"},{"path":"/usr/lib/python3.12/xml/etree"},{"path":"/usr/lib/python3.12/xml/etree/ElementInclude.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementPath.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementTree.py"},{"path":"/usr/lib/python3.12/xml/etree/__init__.py"},{"path":"/usr/lib/python3.12/xml/etree/cElementTree.py"},{"path":"/usr/lib/python3.12/xml/parsers"},{"path":"/usr/lib/python3.12/xml/parsers/__init__.py"},{"path":"/usr/lib/python3.12/xml/parsers/expat.py"},{"path":"/usr/lib/python3.12/xml/sax"},{"path":"/usr/lib/python3.12/xml/sax/__init__.py"},{"path":"/usr/lib/python3.12/xml/sax/_exceptions.py"},{"path":"/usr/lib/python3.12/xml/sax/expatreader.py"},{"path":"/usr/lib/python3.12/xml/sax/handler.py"},{"path":"/usr/lib/python3.12/xml/sax/saxutils.py"},{"path":"/usr/lib/python3.12/xml/sax/xmlreader.py"},{"path":"/usr/lib/python3.12/xmlrpc"},{"path":"/usr/lib/python3.12/xmlrpc/__init__.py"},{"path":"/usr/lib/python3.12/xmlrpc/client.py"},{"path":"/usr/lib/python3.12/xmlrpc/server.py"},{"path":"/usr/lib/python3.12/zipfile"},{"path":"/usr/lib/python3.12/zipfile/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/__main__.py"},{"path":"/usr/lib/python3.12/zipfile/_path"},{"path":"/usr/lib/python3.12/zipfile/_path/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/_path/glob.py"},{"path":"/usr/lib/python3.12/zoneinfo"},{"path":"/usr/lib/python3.12/zoneinfo/__init__.py"},{"path":"/usr/lib/python3.12/zoneinfo/_common.py"},{"path":"/usr/lib/python3.12/zoneinfo/_tzpath.py"},{"path":"/usr/lib/python3.12/zoneinfo/_zoneinfo.py"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3446","versionConstraint":"< 3.13.13||>= 3.14.0, < 3.14.4||>= 3.15.0a1, < 3.15.0a8 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}},{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3446","versionConstraint":"< 3.13.13||>= 3.14.0, < 3.14.4||>= 3.15.0a1, < 3.15.0a8 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.12375000000000001,"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."},"relatedVulnerabilities":[]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-15370","versionConstraint":">= 0.11.0, < 0.11.5||= 0.12.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-15370","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15370","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15370","date":"2026-10-08","epss":0.00168,"percentile":0.05493}],"risk":0.1218,"urls":["https://access.redhat.com/errata/RHSA-2026:47768","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/security/cve/CVE-2026-15370","https://bugzilla.redhat.com/show_bug.cgi?id=2499049"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15370","description":"A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"09c24a4342b1cfdb","cpes":["cpe:2.3:a:python-software-foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.12.15-r0:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:apk/alpine/python3@3.12.15-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"3.12.15-r0","language":"","licenses":["PSF-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/2to3"},{"path":"/usr/bin/2to3-3.12"},{"path":"/usr/bin/pydoc3"},{"path":"/usr/bin/pydoc3.12"},{"path":"/usr/bin/python"},{"path":"/usr/bin/python3"},{"path":"/usr/bin/python3.12"},{"path":"/usr/include"},{"path":"/usr/include/python3.12"},{"path":"/usr/include/python3.12/pyconfig.h"},{"path":"/usr/lib"},{"path":"/usr/lib/libpython3.12.so.1.0"},{"path":"/usr/lib/libpython3.so"},{"path":"/usr/lib/python3.12"},{"path":"/usr/lib/python3.12/EXTERNALLY-MANAGED"},{"path":"/usr/lib/python3.12/LICENSE.txt"},{"path":"/usr/lib/python3.12/__future__.py"},{"path":"/usr/lib/python3.12/__hello__.py"},{"path":"/usr/lib/python3.12/_aix_support.py"},{"path":"/usr/lib/python3.12/_collections_abc.py"},{"path":"/usr/lib/python3.12/_compat_pickle.py"},{"path":"/usr/lib/python3.12/_compression.py"},{"path":"/usr/lib/python3.12/_markupbase.py"},{"path":"/usr/lib/python3.12/_osx_support.py"},{"path":"/usr/lib/python3.12/_py_abc.py"},{"path":"/usr/lib/python3.12/_pydatetime.py"},{"path":"/usr/lib/python3.12/_pydecimal.py"},{"path":"/usr/lib/python3.12/_pyio.py"},{"path":"/usr/lib/python3.12/_pylong.py"},{"path":"/usr/lib/python3.12/_sitebuiltins.py"},{"path":"/usr/lib/python3.12/_strptime.py"},{"path":"/usr/lib/python3.12/_sysconfigdata__linux_x86_64-linux-musl.py"},{"path":"/usr/lib/python3.12/_threading_local.py"},{"path":"/usr/lib/python3.12/_weakrefset.py"},{"path":"/usr/lib/python3.12/abc.py"},{"path":"/usr/lib/python3.12/aifc.py"},{"path":"/usr/lib/python3.12/antigravity.py"},{"path":"/usr/lib/python3.12/argparse.py"},{"path":"/usr/lib/python3.12/ast.py"},{"path":"/usr/lib/python3.12/base64.py"},{"path":"/usr/lib/python3.12/bdb.py"},{"path":"/usr/lib/python3.12/bisect.py"},{"path":"/usr/lib/python3.12/bz2.py"},{"path":"/usr/lib/python3.12/cProfile.py"},{"path":"/usr/lib/python3.12/calendar.py"},{"path":"/usr/lib/python3.12/cgi.py"},{"path":"/usr/lib/python3.12/cgitb.py"},{"path":"/usr/lib/python3.12/chunk.py"},{"path":"/usr/lib/python3.12/cmd.py"},{"path":"/usr/lib/python3.12/code.py"},{"path":"/usr/lib/python3.12/codecs.py"},{"path":"/usr/lib/python3.12/codeop.py"},{"path":"/usr/lib/python3.12/colorsys.py"},{"path":"/usr/lib/python3.12/compileall.py"},{"path":"/usr/lib/python3.12/configparser.py"},{"path":"/usr/lib/python3.12/contextlib.py"},{"path":"/usr/lib/python3.12/contextvars.py"},{"path":"/usr/lib/python3.12/copy.py"},{"path":"/usr/lib/python3.12/copyreg.py"},{"path":"/usr/lib/python3.12/crypt.py"},{"path":"/usr/lib/python3.12/csv.py"},{"path":"/usr/lib/python3.12/dataclasses.py"},{"path":"/usr/lib/python3.12/datetime.py"},{"path":"/usr/lib/python3.12/decimal.py"},{"path":"/usr/lib/python3.12/difflib.py"},{"path":"/usr/lib/python3.12/dis.py"},{"path":"/usr/lib/python3.12/doctest.py"},{"path":"/usr/lib/python3.12/enum.py"},{"path":"/usr/lib/python3.12/filecmp.py"},{"path":"/usr/lib/python3.12/fileinput.py"},{"path":"/usr/lib/python3.12/fnmatch.py"},{"path":"/usr/lib/python3.12/fractions.py"},{"path":"/usr/lib/python3.12/ftplib.py"},{"path":"/usr/lib/python3.12/functools.py"},{"path":"/usr/lib/python3.12/genericpath.py"},{"path":"/usr/lib/python3.12/getopt.py"},{"path":"/usr/lib/python3.12/getpass.py"},{"path":"/usr/lib/python3.12/gettext.py"},{"path":"/usr/lib/python3.12/glob.py"},{"path":"/usr/lib/python3.12/graphlib.py"},{"path":"/usr/lib/python3.12/gzip.py"},{"path":"/usr/lib/python3.12/hashlib.py"},{"path":"/usr/lib/python3.12/heapq.py"},{"path":"/usr/lib/python3.12/hmac.py"},{"path":"/usr/lib/python3.12/imaplib.py"},{"path":"/usr/lib/python3.12/imghdr.py"},{"path":"/usr/lib/python3.12/inspect.py"},{"path":"/usr/lib/python3.12/io.py"},{"path":"/usr/lib/python3.12/ipaddress.py"},{"path":"/usr/lib/python3.12/keyword.py"},{"path":"/usr/lib/python3.12/linecache.py"},{"path":"/usr/lib/python3.12/locale.py"},{"path":"/usr/lib/python3.12/lzma.py"},{"path":"/usr/lib/python3.12/mailbox.py"},{"path":"/usr/lib/python3.12/mailcap.py"},{"path":"/usr/lib/python3.12/mimetypes.py"},{"path":"/usr/lib/python3.12/modulefinder.py"},{"path":"/usr/lib/python3.12/netrc.py"},{"path":"/usr/lib/python3.12/nntplib.py"},{"path":"/usr/lib/python3.12/ntpath.py"},{"path":"/usr/lib/python3.12/nturl2path.py"},{"path":"/usr/lib/python3.12/numbers.py"},{"path":"/usr/lib/python3.12/opcode.py"},{"path":"/usr/lib/python3.12/operator.py"},{"path":"/usr/lib/python3.12/optparse.py"},{"path":"/usr/lib/python3.12/os.py"},{"path":"/usr/lib/python3.12/pathlib.py"},{"path":"/usr/lib/python3.12/pdb.py"},{"path":"/usr/lib/python3.12/pickle.py"},{"path":"/usr/lib/python3.12/pickletools.py"},{"path":"/usr/lib/python3.12/pipes.py"},{"path":"/usr/lib/python3.12/pkgutil.py"},{"path":"/usr/lib/python3.12/platform.py"},{"path":"/usr/lib/python3.12/plistlib.py"},{"path":"/usr/lib/python3.12/poplib.py"},{"path":"/usr/lib/python3.12/posixpath.py"},{"path":"/usr/lib/python3.12/pprint.py"},{"path":"/usr/lib/python3.12/profile.py"},{"path":"/usr/lib/python3.12/pstats.py"},{"path":"/usr/lib/python3.12/pty.py"},{"path":"/usr/lib/python3.12/py_compile.py"},{"path":"/usr/lib/python3.12/pyclbr.py"},{"path":"/usr/lib/python3.12/pydoc.py"},{"path":"/usr/lib/python3.12/queue.py"},{"path":"/usr/lib/python3.12/quopri.py"},{"path":"/usr/lib/python3.12/random.py"},{"path":"/usr/lib/python3.12/reprlib.py"},{"path":"/usr/lib/python3.12/rlcompleter.py"},{"path":"/usr/lib/python3.12/runpy.py"},{"path":"/usr/lib/python3.12/sched.py"},{"path":"/usr/lib/python3.12/secrets.py"},{"path":"/usr/lib/python3.12/selectors.py"},{"path":"/usr/lib/python3.12/shelve.py"},{"path":"/usr/lib/python3.12/shlex.py"},{"path":"/usr/lib/python3.12/shutil.py"},{"path":"/usr/lib/python3.12/signal.py"},{"path":"/usr/lib/python3.12/site.py"},{"path":"/usr/lib/python3.12/smtplib.py"},{"path":"/usr/lib/python3.12/sndhdr.py"},{"path":"/usr/lib/python3.12/socket.py"},{"path":"/usr/lib/python3.12/socketserver.py"},{"path":"/usr/lib/python3.12/sre_compile.py"},{"path":"/usr/lib/python3.12/sre_constants.py"},{"path":"/usr/lib/python3.12/sre_parse.py"},{"path":"/usr/lib/python3.12/ssl.py"},{"path":"/usr/lib/python3.12/stat.py"},{"path":"/usr/lib/python3.12/statistics.py"},{"path":"/usr/lib/python3.12/string.py"},{"path":"/usr/lib/python3.12/stringprep.py"},{"path":"/usr/lib/python3.12/struct.py"},{"path":"/usr/lib/python3.12/subprocess.py"},{"path":"/usr/lib/python3.12/sunau.py"},{"path":"/usr/lib/python3.12/symtable.py"},{"path":"/usr/lib/python3.12/sysconfig.py"},{"path":"/usr/lib/python3.12/tabnanny.py"},{"path":"/usr/lib/python3.12/tarfile.py"},{"path":"/usr/lib/python3.12/telnetlib.py"},{"path":"/usr/lib/python3.12/tempfile.py"},{"path":"/usr/lib/python3.12/textwrap.py"},{"path":"/usr/lib/python3.12/this.py"},{"path":"/usr/lib/python3.12/threading.py"},{"path":"/usr/lib/python3.12/timeit.py"},{"path":"/usr/lib/python3.12/token.py"},{"path":"/usr/lib/python3.12/tokenize.py"},{"path":"/usr/lib/python3.12/trace.py"},{"path":"/usr/lib/python3.12/traceback.py"},{"path":"/usr/lib/python3.12/tracemalloc.py"},{"path":"/usr/lib/python3.12/tty.py"},{"path":"/usr/lib/python3.12/turtle.py"},{"path":"/usr/lib/python3.12/types.py"},{"path":"/usr/lib/python3.12/typing.py"},{"path":"/usr/lib/python3.12/uu.py"},{"path":"/usr/lib/python3.12/uuid.py"},{"path":"/usr/lib/python3.12/warnings.py"},{"path":"/usr/lib/python3.12/wave.py"},{"path":"/usr/lib/python3.12/weakref.py"},{"path":"/usr/lib/python3.12/webbrowser.py"},{"path":"/usr/lib/python3.12/xdrlib.py"},{"path":"/usr/lib/python3.12/zipapp.py"},{"path":"/usr/lib/python3.12/zipimport.py"},{"path":"/usr/lib/python3.12/__phello__"},{"path":"/usr/lib/python3.12/__phello__/__init__.py"},{"path":"/usr/lib/python3.12/__phello__/spam.py"},{"path":"/usr/lib/python3.12/asyncio"},{"path":"/usr/lib/python3.12/asyncio/__init__.py"},{"path":"/usr/lib/python3.12/asyncio/__main__.py"},{"path":"/usr/lib/python3.12/asyncio/base_events.py"},{"path":"/usr/lib/python3.12/asyncio/base_futures.py"},{"path":"/usr/lib/python3.12/asyncio/base_subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/base_tasks.py"},{"path":"/usr/lib/python3.12/asyncio/constants.py"},{"path":"/usr/lib/python3.12/asyncio/coroutines.py"},{"path":"/usr/lib/python3.12/asyncio/events.py"},{"path":"/usr/lib/python3.12/asyncio/exceptions.py"},{"path":"/usr/lib/python3.12/asyncio/format_helpers.py"},{"path":"/usr/lib/python3.12/asyncio/futures.py"},{"path":"/usr/lib/python3.12/asyncio/locks.py"},{"path":"/usr/lib/python3.12/asyncio/log.py"},{"path":"/usr/lib/python3.12/asyncio/mixins.py"},{"path":"/usr/lib/python3.12/asyncio/proactor_events.py"},{"path":"/usr/lib/python3.12/asyncio/protocols.py"},{"path":"/usr/lib/python3.12/asyncio/queues.py"},{"path":"/usr/lib/python3.12/asyncio/runners.py"},{"path":"/usr/lib/python3.12/asyncio/selector_events.py"},{"path":"/usr/lib/python3.12/asyncio/sslproto.py"},{"path":"/usr/lib/python3.12/asyncio/staggered.py"},{"path":"/usr/lib/python3.12/asyncio/streams.py"},{"path":"/usr/lib/python3.12/asyncio/subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/taskgroups.py"},{"path":"/usr/lib/python3.12/asyncio/tasks.py"},{"path":"/usr/lib/python3.12/asyncio/threads.py"},{"path":"/usr/lib/python3.12/asyncio/timeouts.py"},{"path":"/usr/lib/python3.12/asyncio/transports.py"},{"path":"/usr/lib/python3.12/asyncio/trsock.py"},{"path":"/usr/lib/python3.12/asyncio/unix_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_utils.py"},{"path":"/usr/lib/python3.12/collections"},{"path":"/usr/lib/python3.12/collections/__init__.py"},{"path":"/usr/lib/python3.12/collections/abc.py"},{"path":"/usr/lib/python3.12/concurrent"},{"path":"/usr/lib/python3.12/concurrent/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures"},{"path":"/usr/lib/python3.12/concurrent/futures/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures/_base.py"},{"path":"/usr/lib/python3.12/concurrent/futures/process.py"},{"path":"/usr/lib/python3.12/concurrent/futures/thread.py"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Makefile"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.bootstrap"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.local"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.stdlib"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/config.c.in"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/install-sh"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/makesetup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/python-config.py"},{"path":"/usr/lib/python3.12/ctypes"},{"path":"/usr/lib/python3.12/ctypes/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/_aix.py"},{"path":"/usr/lib/python3.12/ctypes/_endian.py"},{"path":"/usr/lib/python3.12/ctypes/util.py"},{"path":"/usr/lib/python3.12/ctypes/wintypes.py"},{"path":"/usr/lib/python3.12/ctypes/macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/README.ctypes"},{"path":"/usr/lib/python3.12/ctypes/macholib/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dyld.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dylib.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib.bat"},{"path":"/usr/lib/python3.12/ctypes/macholib/framework.py"},{"path":"/usr/lib/python3.12/curses"},{"path":"/usr/lib/python3.12/curses/__init__.py"},{"path":"/usr/lib/python3.12/curses/ascii.py"},{"path":"/usr/lib/python3.12/curses/has_key.py"},{"path":"/usr/lib/python3.12/curses/panel.py"},{"path":"/usr/lib/python3.12/curses/textpad.py"},{"path":"/usr/lib/python3.12/dbm"},{"path":"/usr/lib/python3.12/dbm/__init__.py"},{"path":"/usr/lib/python3.12/dbm/dumb.py"},{"path":"/usr/lib/python3.12/dbm/gnu.py"},{"path":"/usr/lib/python3.12/dbm/ndbm.py"},{"path":"/usr/lib/python3.12/email"},{"path":"/usr/lib/python3.12/email/__init__.py"},{"path":"/usr/lib/python3.12/email/_encoded_words.py"},{"path":"/usr/lib/python3.12/email/_header_value_parser.py"},{"path":"/usr/lib/python3.12/email/_parseaddr.py"},{"path":"/usr/lib/python3.12/email/_policybase.py"},{"path":"/usr/lib/python3.12/email/architecture.rst"},{"path":"/usr/lib/python3.12/email/base64mime.py"},{"path":"/usr/lib/python3.12/email/charset.py"},{"path":"/usr/lib/python3.12/email/contentmanager.py"},{"path":"/usr/lib/python3.12/email/encoders.py"},{"path":"/usr/lib/python3.12/email/errors.py"},{"path":"/usr/lib/python3.12/email/feedparser.py"},{"path":"/usr/lib/python3.12/email/generator.py"},{"path":"/usr/lib/python3.12/email/header.py"},{"path":"/usr/lib/python3.12/email/headerregistry.py"},{"path":"/usr/lib/python3.12/email/iterators.py"},{"path":"/usr/lib/python3.12/email/message.py"},{"path":"/usr/lib/python3.12/email/parser.py"},{"path":"/usr/lib/python3.12/email/policy.py"},{"path":"/usr/lib/python3.12/email/quoprimime.py"},{"path":"/usr/lib/python3.12/email/utils.py"},{"path":"/usr/lib/python3.12/email/mime"},{"path":"/usr/lib/python3.12/email/mime/__init__.py"},{"path":"/usr/lib/python3.12/email/mime/application.py"},{"path":"/usr/lib/python3.12/email/mime/audio.py"},{"path":"/usr/lib/python3.12/email/mime/base.py"},{"path":"/usr/lib/python3.12/email/mime/image.py"},{"path":"/usr/lib/python3.12/email/mime/message.py"},{"path":"/usr/lib/python3.12/email/mime/multipart.py"},{"path":"/usr/lib/python3.12/email/mime/nonmultipart.py"},{"path":"/usr/lib/python3.12/email/mime/text.py"},{"path":"/usr/lib/python3.12/encodings"},{"path":"/usr/lib/python3.12/encodings/__init__.py"},{"path":"/usr/lib/python3.12/encodings/aliases.py"},{"path":"/usr/lib/python3.12/encodings/ascii.py"},{"path":"/usr/lib/python3.12/encodings/base64_codec.py"},{"path":"/usr/lib/python3.12/encodings/big5.py"},{"path":"/usr/lib/python3.12/encodings/big5hkscs.py"},{"path":"/usr/lib/python3.12/encodings/bz2_codec.py"},{"path":"/usr/lib/python3.12/encodings/charmap.py"},{"path":"/usr/lib/python3.12/encodings/cp037.py"},{"path":"/usr/lib/python3.12/encodings/cp1006.py"},{"path":"/usr/lib/python3.12/encodings/cp1026.py"},{"path":"/usr/lib/python3.12/encodings/cp1125.py"},{"path":"/usr/lib/python3.12/encodings/cp1140.py"},{"path":"/usr/lib/python3.12/encodings/cp1250.py"},{"path":"/usr/lib/python3.12/encodings/cp1251.py"},{"path":"/usr/lib/python3.12/encodings/cp1252.py"},{"path":"/usr/lib/python3.12/encodings/cp1253.py"},{"path":"/usr/lib/python3.12/encodings/cp1254.py"},{"path":"/usr/lib/python3.12/encodings/cp1255.py"},{"path":"/usr/lib/python3.12/encodings/cp1256.py"},{"path":"/usr/lib/python3.12/encodings/cp1257.py"},{"path":"/usr/lib/python3.12/encodings/cp1258.py"},{"path":"/usr/lib/python3.12/encodings/cp273.py"},{"path":"/usr/lib/python3.12/encodings/cp424.py"},{"path":"/usr/lib/python3.12/encodings/cp437.py"},{"path":"/usr/lib/python3.12/encodings/cp500.py"},{"path":"/usr/lib/python3.12/encodings/cp720.py"},{"path":"/usr/lib/python3.12/encodings/cp737.py"},{"path":"/usr/lib/python3.12/encodings/cp775.py"},{"path":"/usr/lib/python3.12/encodings/cp850.py"},{"path":"/usr/lib/python3.12/encodings/cp852.py"},{"path":"/usr/lib/python3.12/encodings/cp855.py"},{"path":"/usr/lib/python3.12/encodings/cp856.py"},{"path":"/usr/lib/python3.12/encodings/cp857.py"},{"path":"/usr/lib/python3.12/encodings/cp858.py"},{"path":"/usr/lib/python3.12/encodings/cp860.py"},{"path":"/usr/lib/python3.12/encodings/cp861.py"},{"path":"/usr/lib/python3.12/encodings/cp862.py"},{"path":"/usr/lib/python3.12/encodings/cp863.py"},{"path":"/usr/lib/python3.12/encodings/cp864.py"},{"path":"/usr/lib/python3.12/encodings/cp865.py"},{"path":"/usr/lib/python3.12/encodings/cp866.py"},{"path":"/usr/lib/python3.12/encodings/cp869.py"},{"path":"/usr/lib/python3.12/encodings/cp874.py"},{"path":"/usr/lib/python3.12/encodings/cp875.py"},{"path":"/usr/lib/python3.12/encodings/cp932.py"},{"path":"/usr/lib/python3.12/encodings/cp949.py"},{"path":"/usr/lib/python3.12/encodings/cp950.py"},{"path":"/usr/lib/python3.12/encodings/euc_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/euc_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/euc_jp.py"},{"path":"/usr/lib/python3.12/encodings/euc_kr.py"},{"path":"/usr/lib/python3.12/encodings/gb18030.py"},{"path":"/usr/lib/python3.12/encodings/gb2312.py"},{"path":"/usr/lib/python3.12/encodings/gbk.py"},{"path":"/usr/lib/python3.12/encodings/hex_codec.py"},{"path":"/usr/lib/python3.12/encodings/hp_roman8.py"},{"path":"/usr/lib/python3.12/encodings/hz.py"},{"path":"/usr/lib/python3.12/encodings/idna.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_1.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2004.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_3.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_ext.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_kr.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_1.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_10.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_11.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_13.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_14.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_15.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_16.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_2.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_3.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_4.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_5.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_6.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_7.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_8.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_9.py"},{"path":"/usr/lib/python3.12/encodings/johab.py"},{"path":"/usr/lib/python3.12/encodings/koi8_r.py"},{"path":"/usr/lib/python3.12/encodings/koi8_t.py"},{"path":"/usr/lib/python3.12/encodings/koi8_u.py"},{"path":"/usr/lib/python3.12/encodings/kz1048.py"},{"path":"/usr/lib/python3.12/encodings/latin_1.py"},{"path":"/usr/lib/python3.12/encodings/mac_arabic.py"},{"path":"/usr/lib/python3.12/encodings/mac_croatian.py"},{"path":"/usr/lib/python3.12/encodings/mac_cyrillic.py"},{"path":"/usr/lib/python3.12/encodings/mac_farsi.py"},{"path":"/usr/lib/python3.12/encodings/mac_greek.py"},{"path":"/usr/lib/python3.12/encodings/mac_iceland.py"},{"path":"/usr/lib/python3.12/encodings/mac_latin2.py"},{"path":"/usr/lib/python3.12/encodings/mac_roman.py"},{"path":"/usr/lib/python3.12/encodings/mac_romanian.py"},{"path":"/usr/lib/python3.12/encodings/mac_turkish.py"},{"path":"/usr/lib/python3.12/encodings/mbcs.py"},{"path":"/usr/lib/python3.12/encodings/oem.py"},{"path":"/usr/lib/python3.12/encodings/palmos.py"},{"path":"/usr/lib/python3.12/encodings/ptcp154.py"},{"path":"/usr/lib/python3.12/encodings/punycode.py"},{"path":"/usr/lib/python3.12/encodings/quopri_codec.py"},{"path":"/usr/lib/python3.12/encodings/raw_unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/rot_13.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/shift_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/tis_620.py"},{"path":"/usr/lib/python3.12/encodings/undefined.py"},{"path":"/usr/lib/python3.12/encodings/unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/utf_16.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_32.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_7.py"},{"path":"/usr/lib/python3.12/encodings/utf_8.py"},{"path":"/usr/lib/python3.12/encodings/utf_8_sig.py"},{"path":"/usr/lib/python3.12/encodings/uu_codec.py"},{"path":"/usr/lib/python3.12/encodings/zlib_codec.py"},{"path":"/usr/lib/python3.12/ensurepip"},{"path":"/usr/lib/python3.12/ensurepip/__init__.py"},{"path":"/usr/lib/python3.12/ensurepip/__main__.py"},{"path":"/usr/lib/python3.12/ensurepip/_uninstall.py"},{"path":"/usr/lib/python3.12/ensurepip/_bundled"},{"path":"/usr/lib/python3.12/ensurepip/_bundled/pip-25.0.1-py3-none-any.whl"},{"path":"/usr/lib/python3.12/html"},{"path":"/usr/lib/python3.12/html/__init__.py"},{"path":"/usr/lib/python3.12/html/entities.py"},{"path":"/usr/lib/python3.12/html/parser.py"},{"path":"/usr/lib/python3.12/http"},{"path":"/usr/lib/python3.12/http/__init__.py"},{"path":"/usr/lib/python3.12/http/client.py"},{"path":"/usr/lib/python3.12/http/cookiejar.py"},{"path":"/usr/lib/python3.12/http/cookies.py"},{"path":"/usr/lib/python3.12/http/server.py"},{"path":"/usr/lib/python3.12/importlib"},{"path":"/usr/lib/python3.12/importlib/__init__.py"},{"path":"/usr/lib/python3.12/importlib/_abc.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap_external.py"},{"path":"/usr/lib/python3.12/importlib/abc.py"},{"path":"/usr/lib/python3.12/importlib/machinery.py"},{"path":"/usr/lib/python3.12/importlib/readers.py"},{"path":"/usr/lib/python3.12/importlib/simple.py"},{"path":"/usr/lib/python3.12/importlib/util.py"},{"path":"/usr/lib/python3.12/importlib/metadata"},{"path":"/usr/lib/python3.12/importlib/metadata/__init__.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_collections.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_functools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_meta.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_text.py"},{"path":"/usr/lib/python3.12/importlib/resources"},{"path":"/usr/lib/python3.12/importlib/resources/__init__.py"},{"path":"/usr/lib/python3.12/importlib/resources/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/resources/_common.py"},{"path":"/usr/lib/python3.12/importlib/resources/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/resources/_legacy.py"},{"path":"/usr/lib/python3.12/importlib/resources/abc.py"},{"path":"/usr/lib/python3.12/importlib/resources/readers.py"},{"path":"/usr/lib/python3.12/importlib/resources/simple.py"},{"path":"/usr/lib/python3.12/json"},{"path":"/usr/lib/python3.12/json/__init__.py"},{"path":"/usr/lib/python3.12/json/decoder.py"},{"path":"/usr/lib/python3.12/json/encoder.py"},{"path":"/usr/lib/python3.12/json/scanner.py"},{"path":"/usr/lib/python3.12/json/tool.py"},{"path":"/usr/lib/python3.12/lib-dynload"},{"path":"/usr/lib/python3.12/lib-dynload/_asyncio.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bisect.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_blake2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bz2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_cn.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_hk.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_iso2022.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_jp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_kr.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_tw.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_contextvars.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_crypt.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_csv.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes_test.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses_panel.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_datetime.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_dbm.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_decimal.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_elementtree.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_hashlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_heapq.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_json.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lsprof.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lzma.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_md5.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multibytecodec.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multiprocessing.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_opcode.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_pickle.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixshmem.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixsubprocess.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_queue.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_random.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha1.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_socket.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sqlite3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ssl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_statistics.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_struct.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testbuffer.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testclinic.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testimportmultiple.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testinternalcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testmultiphase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testsinglephase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxinterpchannels.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxsubinterpreters.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxtestfuzz.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_zoneinfo.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/array.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/audioop.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/binascii.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/cmath.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/fcntl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/grp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/math.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/mmap.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/ossaudiodev.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/pyexpat.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/readline.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/resource.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/select.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/spwd.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/syslog.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/termios.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/unicodedata.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited_35.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxsubtype.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/zlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib2to3"},{"path":"/usr/lib/python3.12/lib2to3/Grammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/Grammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/__main__.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_matcher.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_utils.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_base.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_util.py"},{"path":"/usr/lib/python3.12/lib2to3/main.py"},{"path":"/usr/lib/python3.12/lib2to3/patcomp.py"},{"path":"/usr/lib/python3.12/lib2to3/pygram.py"},{"path":"/usr/lib/python3.12/lib2to3/pytree.py"},{"path":"/usr/lib/python3.12/lib2to3/refactor.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes"},{"path":"/usr/lib/python3.12/lib2to3/fixes/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_apply.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_asserts.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_basestring.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_buffer.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_dict.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_except.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exec.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_execfile.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exitfunc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_filter.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_funcattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_future.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_getcwdu.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_has_key.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_idioms.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_import.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports2.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_intern.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_isinstance.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_long.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_map.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_metaclass.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_methodattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ne.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_next.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_nonzero.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_numliterals.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_operator.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_paren.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_print.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raise.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raw_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reduce.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reload.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_renames.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_repr.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_set_literal.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_standarderror.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_sys_exc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_throw.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_tuple_params.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_types.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_unicode.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_urllib.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ws_comma.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xrange.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xreadlines.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_zip.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/conv.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/driver.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/grammar.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/literals.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/parse.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/pgen.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/token.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/tokenize.py"},{"path":"/usr/lib/python3.12/logging"},{"path":"/usr/lib/python3.12/logging/__init__.py"},{"path":"/usr/lib/python3.12/logging/config.py"},{"path":"/usr/lib/python3.12/logging/handlers.py"},{"path":"/usr/lib/python3.12/multiprocessing"},{"path":"/usr/lib/python3.12/multiprocessing/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/connection.py"},{"path":"/usr/lib/python3.12/multiprocessing/context.py"},{"path":"/usr/lib/python3.12/multiprocessing/forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/heap.py"},{"path":"/usr/lib/python3.12/multiprocessing/managers.py"},{"path":"/usr/lib/python3.12/multiprocessing/pool.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_fork.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_posix.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_win32.py"},{"path":"/usr/lib/python3.12/multiprocessing/process.py"},{"path":"/usr/lib/python3.12/multiprocessing/queues.py"},{"path":"/usr/lib/python3.12/multiprocessing/reduction.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_sharer.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_tracker.py"},{"path":"/usr/lib/python3.12/multiprocessing/shared_memory.py"},{"path":"/usr/lib/python3.12/multiprocessing/sharedctypes.py"},{"path":"/usr/lib/python3.12/multiprocessing/spawn.py"},{"path":"/usr/lib/python3.12/multiprocessing/synchronize.py"},{"path":"/usr/lib/python3.12/multiprocessing/util.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/connection.py"},{"path":"/usr/lib/python3.12/pydoc_data"},{"path":"/usr/lib/python3.12/pydoc_data/__init__.py"},{"path":"/usr/lib/python3.12/pydoc_data/_pydoc.css"},{"path":"/usr/lib/python3.12/pydoc_data/topics.py"},{"path":"/usr/lib/python3.12/re"},{"path":"/usr/lib/python3.12/re/__init__.py"},{"path":"/usr/lib/python3.12/re/_casefix.py"},{"path":"/usr/lib/python3.12/re/_compiler.py"},{"path":"/usr/lib/python3.12/re/_constants.py"},{"path":"/usr/lib/python3.12/re/_parser.py"},{"path":"/usr/lib/python3.12/site-packages"},{"path":"/usr/lib/python3.12/site-packages/README.txt"},{"path":"/usr/lib/python3.12/sqlite3"},{"path":"/usr/lib/python3.12/sqlite3/__init__.py"},{"path":"/usr/lib/python3.12/sqlite3/__main__.py"},{"path":"/usr/lib/python3.12/sqlite3/dbapi2.py"},{"path":"/usr/lib/python3.12/sqlite3/dump.py"},{"path":"/usr/lib/python3.12/tomllib"},{"path":"/usr/lib/python3.12/tomllib/__init__.py"},{"path":"/usr/lib/python3.12/tomllib/_parser.py"},{"path":"/usr/lib/python3.12/tomllib/_re.py"},{"path":"/usr/lib/python3.12/tomllib/_types.py"},{"path":"/usr/lib/python3.12/turtledemo"},{"path":"/usr/lib/python3.12/turtledemo/__init__.py"},{"path":"/usr/lib/python3.12/turtledemo/__main__.py"},{"path":"/usr/lib/python3.12/turtledemo/bytedesign.py"},{"path":"/usr/lib/python3.12/turtledemo/chaos.py"},{"path":"/usr/lib/python3.12/turtledemo/clock.py"},{"path":"/usr/lib/python3.12/turtledemo/colormixer.py"},{"path":"/usr/lib/python3.12/turtledemo/forest.py"},{"path":"/usr/lib/python3.12/turtledemo/fractalcurves.py"},{"path":"/usr/lib/python3.12/turtledemo/lindenmayer.py"},{"path":"/usr/lib/python3.12/turtledemo/minimal_hanoi.py"},{"path":"/usr/lib/python3.12/turtledemo/nim.py"},{"path":"/usr/lib/python3.12/turtledemo/paint.py"},{"path":"/usr/lib/python3.12/turtledemo/peace.py"},{"path":"/usr/lib/python3.12/turtledemo/penrose.py"},{"path":"/usr/lib/python3.12/turtledemo/planet_and_moon.py"},{"path":"/usr/lib/python3.12/turtledemo/rosette.py"},{"path":"/usr/lib/python3.12/turtledemo/round_dance.py"},{"path":"/usr/lib/python3.12/turtledemo/sorting_animate.py"},{"path":"/usr/lib/python3.12/turtledemo/tree.py"},{"path":"/usr/lib/python3.12/turtledemo/turtle.cfg"},{"path":"/usr/lib/python3.12/turtledemo/two_canvases.py"},{"path":"/usr/lib/python3.12/turtledemo/yinyang.py"},{"path":"/usr/lib/python3.12/unittest"},{"path":"/usr/lib/python3.12/unittest/__init__.py"},{"path":"/usr/lib/python3.12/unittest/__main__.py"},{"path":"/usr/lib/python3.12/unittest/_log.py"},{"path":"/usr/lib/python3.12/unittest/async_case.py"},{"path":"/usr/lib/python3.12/unittest/case.py"},{"path":"/usr/lib/python3.12/unittest/loader.py"},{"path":"/usr/lib/python3.12/unittest/main.py"},{"path":"/usr/lib/python3.12/unittest/mock.py"},{"path":"/usr/lib/python3.12/unittest/result.py"},{"path":"/usr/lib/python3.12/unittest/runner.py"},{"path":"/usr/lib/python3.12/unittest/signals.py"},{"path":"/usr/lib/python3.12/unittest/suite.py"},{"path":"/usr/lib/python3.12/unittest/util.py"},{"path":"/usr/lib/python3.12/urllib"},{"path":"/usr/lib/python3.12/urllib/__init__.py"},{"path":"/usr/lib/python3.12/urllib/error.py"},{"path":"/usr/lib/python3.12/urllib/parse.py"},{"path":"/usr/lib/python3.12/urllib/request.py"},{"path":"/usr/lib/python3.12/urllib/response.py"},{"path":"/usr/lib/python3.12/urllib/robotparser.py"},{"path":"/usr/lib/python3.12/venv"},{"path":"/usr/lib/python3.12/venv/__init__.py"},{"path":"/usr/lib/python3.12/venv/__main__.py"},{"path":"/usr/lib/python3.12/venv/scripts"},{"path":"/usr/lib/python3.12/venv/scripts/common"},{"path":"/usr/lib/python3.12/venv/scripts/common/Activate.ps1"},{"path":"/usr/lib/python3.12/venv/scripts/common/activate"},{"path":"/usr/lib/python3.12/venv/scripts/posix"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.csh"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.fish"},{"path":"/usr/lib/python3.12/wsgiref"},{"path":"/usr/lib/python3.12/wsgiref/__init__.py"},{"path":"/usr/lib/python3.12/wsgiref/handlers.py"},{"path":"/usr/lib/python3.12/wsgiref/headers.py"},{"path":"/usr/lib/python3.12/wsgiref/simple_server.py"},{"path":"/usr/lib/python3.12/wsgiref/types.py"},{"path":"/usr/lib/python3.12/wsgiref/util.py"},{"path":"/usr/lib/python3.12/wsgiref/validate.py"},{"path":"/usr/lib/python3.12/xml"},{"path":"/usr/lib/python3.12/xml/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom"},{"path":"/usr/lib/python3.12/xml/dom/NodeFilter.py"},{"path":"/usr/lib/python3.12/xml/dom/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom/domreg.py"},{"path":"/usr/lib/python3.12/xml/dom/expatbuilder.py"},{"path":"/usr/lib/python3.12/xml/dom/minicompat.py"},{"path":"/usr/lib/python3.12/xml/dom/minidom.py"},{"path":"/usr/lib/python3.12/xml/dom/pulldom.py"},{"path":"/usr/lib/python3.12/xml/dom/xmlbuilder.py"},{"path":"/usr/lib/python3.12/xml/etree"},{"path":"/usr/lib/python3.12/xml/etree/ElementInclude.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementPath.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementTree.py"},{"path":"/usr/lib/python3.12/xml/etree/__init__.py"},{"path":"/usr/lib/python3.12/xml/etree/cElementTree.py"},{"path":"/usr/lib/python3.12/xml/parsers"},{"path":"/usr/lib/python3.12/xml/parsers/__init__.py"},{"path":"/usr/lib/python3.12/xml/parsers/expat.py"},{"path":"/usr/lib/python3.12/xml/sax"},{"path":"/usr/lib/python3.12/xml/sax/__init__.py"},{"path":"/usr/lib/python3.12/xml/sax/_exceptions.py"},{"path":"/usr/lib/python3.12/xml/sax/expatreader.py"},{"path":"/usr/lib/python3.12/xml/sax/handler.py"},{"path":"/usr/lib/python3.12/xml/sax/saxutils.py"},{"path":"/usr/lib/python3.12/xml/sax/xmlreader.py"},{"path":"/usr/lib/python3.12/xmlrpc"},{"path":"/usr/lib/python3.12/xmlrpc/__init__.py"},{"path":"/usr/lib/python3.12/xmlrpc/client.py"},{"path":"/usr/lib/python3.12/xmlrpc/server.py"},{"path":"/usr/lib/python3.12/zipfile"},{"path":"/usr/lib/python3.12/zipfile/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/__main__.py"},{"path":"/usr/lib/python3.12/zipfile/_path"},{"path":"/usr/lib/python3.12/zipfile/_path/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/_path/glob.py"},{"path":"/usr/lib/python3.12/zoneinfo"},{"path":"/usr/lib/python3.12/zoneinfo/__init__.py"},{"path":"/usr/lib/python3.12/zoneinfo/_common.py"},{"path":"/usr/lib/python3.12/zoneinfo/_tzpath.py"},{"path":"/usr/lib/python3.12/zoneinfo/_zoneinfo.py"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-12345","versionConstraint":"< 3.15.0rc3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}},{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-12345","versionConstraint":"< 3.15.0rc3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.0981,"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"746a5398c68762fd","cpes":["cpe:2.3:a:coreutils:coreutils:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.8-r1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.8-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"9.8-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/chcon"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/runcon"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.8:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.8-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"80fc7e85cd2608c5","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.8-r1:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.8-r1?arch=x86_64&distro=alpine-3.23.6&upstream=coreutils","type":"apk","version":"9.8-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.8:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.8-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"68b3fbeb4ac465f1","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.8-r1:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.8-r1?arch=x86_64&distro=alpine-3.23.6&upstream=coreutils","type":"apk","version":"9.8-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.8:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.8-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"b7fbe9298b523216","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.8-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.8-r1:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.8-r1?arch=x86_64&distro=alpine-3.23.6&upstream=coreutils","type":"apk","version":"9.8-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.8:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.8-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"d033f6e836718f4b","cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-project:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:apk/alpine/alsa-lib@1.2.14-r2?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"1.2.14-r2","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/alsa"},{"path":"/etc/alsa/conf.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/aserver"},{"path":"/usr/lib"},{"path":"/usr/lib/libasound.so.2"},{"path":"/usr/lib/libasound.so.2.0.0"},{"path":"/usr/lib/libatopology.so.2"},{"path":"/usr/lib/libatopology.so.2.0.0"},{"path":"/usr/share"},{"path":"/usr/share/alsa"},{"path":"/usr/share/alsa/alsa.conf"},{"path":"/usr/share/alsa/cards"},{"path":"/usr/share/alsa/cards/AACI.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-MODEM.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-SPDMA.conf"},{"path":"/usr/share/alsa/cards/ATIIXP.conf"},{"path":"/usr/share/alsa/cards/AU8810.conf"},{"path":"/usr/share/alsa/cards/AU8820.conf"},{"path":"/usr/share/alsa/cards/AU8830.conf"},{"path":"/usr/share/alsa/cards/Audigy.conf"},{"path":"/usr/share/alsa/cards/Audigy2.conf"},{"path":"/usr/share/alsa/cards/Aureon51.conf"},{"path":"/usr/share/alsa/cards/Aureon71.conf"},{"path":"/usr/share/alsa/cards/CA0106.conf"},{"path":"/usr/share/alsa/cards/CMI8338-SWIEC.conf"},{"path":"/usr/share/alsa/cards/CMI8338.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC6.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC8.conf"},{"path":"/usr/share/alsa/cards/CMI8788.conf"},{"path":"/usr/share/alsa/cards/CS46xx.conf"},{"path":"/usr/share/alsa/cards/EMU10K1.conf"},{"path":"/usr/share/alsa/cards/EMU10K1X.conf"},{"path":"/usr/share/alsa/cards/ENS1370.conf"},{"path":"/usr/share/alsa/cards/ENS1371.conf"},{"path":"/usr/share/alsa/cards/ES1968.conf"},{"path":"/usr/share/alsa/cards/Echo_Echo3G.conf"},{"path":"/usr/share/alsa/cards/FM801.conf"},{"path":"/usr/share/alsa/cards/FWSpeakers.conf"},{"path":"/usr/share/alsa/cards/FireWave.conf"},{"path":"/usr/share/alsa/cards/GUS.conf"},{"path":"/usr/share/alsa/cards/HDA-Intel.conf"},{"path":"/usr/share/alsa/cards/HdmiLpeAudio.conf"},{"path":"/usr/share/alsa/cards/ICE1712.conf"},{"path":"/usr/share/alsa/cards/ICE1724.conf"},{"path":"/usr/share/alsa/cards/ICH-MODEM.conf"},{"path":"/usr/share/alsa/cards/ICH.conf"},{"path":"/usr/share/alsa/cards/ICH4.conf"},{"path":"/usr/share/alsa/cards/Loopback.conf"},{"path":"/usr/share/alsa/cards/Maestro3.conf"},{"path":"/usr/share/alsa/cards/NFORCE.conf"},{"path":"/usr/share/alsa/cards/PC-Speaker.conf"},{"path":"/usr/share/alsa/cards/PMac.conf"},{"path":"/usr/share/alsa/cards/PMacToonie.conf"},{"path":"/usr/share/alsa/cards/PS3.conf"},{"path":"/usr/share/alsa/cards/RME9636.conf"},{"path":"/usr/share/alsa/cards/RME9652.conf"},{"path":"/usr/share/alsa/cards/SB-XFi.conf"},{"path":"/usr/share/alsa/cards/SI7018.conf"},{"path":"/usr/share/alsa/cards/TRID4DWAVENX.conf"},{"path":"/usr/share/alsa/cards/USB-Audio.conf"},{"path":"/usr/share/alsa/cards/VIA686A.conf"},{"path":"/usr/share/alsa/cards/VIA8233.conf"},{"path":"/usr/share/alsa/cards/VIA8233A.conf"},{"path":"/usr/share/alsa/cards/VIA8237.conf"},{"path":"/usr/share/alsa/cards/VX222.conf"},{"path":"/usr/share/alsa/cards/VXPocket.conf"},{"path":"/usr/share/alsa/cards/VXPocket440.conf"},{"path":"/usr/share/alsa/cards/YMF744.conf"},{"path":"/usr/share/alsa/cards/aliases.conf"},{"path":"/usr/share/alsa/cards/pistachio-card.conf"},{"path":"/usr/share/alsa/cards/vc4-hdmi.conf"},{"path":"/usr/share/alsa/ctl"},{"path":"/usr/share/alsa/ctl/default.conf"},{"path":"/usr/share/alsa/pcm"},{"path":"/usr/share/alsa/pcm/center_lfe.conf"},{"path":"/usr/share/alsa/pcm/default.conf"},{"path":"/usr/share/alsa/pcm/dmix.conf"},{"path":"/usr/share/alsa/pcm/dpl.conf"},{"path":"/usr/share/alsa/pcm/dsnoop.conf"},{"path":"/usr/share/alsa/pcm/front.conf"},{"path":"/usr/share/alsa/pcm/hdmi.conf"},{"path":"/usr/share/alsa/pcm/iec958.conf"},{"path":"/usr/share/alsa/pcm/modem.conf"},{"path":"/usr/share/alsa/pcm/rear.conf"},{"path":"/usr/share/alsa/pcm/side.conf"},{"path":"/usr/share/alsa/pcm/surround21.conf"},{"path":"/usr/share/alsa/pcm/surround40.conf"},{"path":"/usr/share/alsa/pcm/surround41.conf"},{"path":"/usr/share/alsa/pcm/surround50.conf"},{"path":"/usr/share/alsa/pcm/surround51.conf"},{"path":"/usr/share/alsa/pcm/surround71.conf"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"alsa-lib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-90781","versionConstraint":"<= 1.2.16.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14:*:*:*:*:*:*:*"],"package":{"name":"alsa-lib","version":"1.2.14-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-90781","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90781","cwe":"CWE-193","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-90781","date":"2026-10-08","epss":0.0017,"percentile":0.0582}],"risk":0.08159999999999999,"urls":["https://github.com/alsa-project/alsa-lib","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241","https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020","https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/","https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90781","description":"alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1ce7c6430fd1308","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12343","versionConstraint":">= 6.1, < 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12343","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12343","cwe":"CWE-415","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-12343","date":"2026-10-08","epss":0.00159,"percentile":0.0441}],"risk":0.07473,"urls":["https://access.redhat.com/security/cve/CVE-2025-12343","https://bugzilla.redhat.com/show_bug.cgi?id=2406533"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12343","description":"A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"47e4a6e79e9b6097","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.11.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12343","versionConstraint":">= 6.1, < 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12343","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12343","cwe":"CWE-415","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-12343","date":"2026-10-08","epss":0.00159,"percentile":0.0441}],"risk":0.07473,"urls":["https://access.redhat.com/security/cve/CVE-2025-12343","https://bugzilla.redhat.com/show_bug.cgi?id=2406533"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12343","description":"A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"6b62aa5bcd47d8ac","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.62"},{"path":"/usr/lib/libavdevice.so.62.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12343","versionConstraint":">= 6.1, < 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12343","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12343","cwe":"CWE-415","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-12343","date":"2026-10-08","epss":0.00159,"percentile":0.0441}],"risk":0.07473,"urls":["https://access.redhat.com/security/cve/CVE-2025-12343","https://bugzilla.redhat.com/show_bug.cgi?id=2406533"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12343","description":"A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"3356a66f4e13c539","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.11"},{"path":"/usr/lib/libavfilter.so.11.4.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12343","versionConstraint":">= 6.1, < 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12343","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12343","cwe":"CWE-415","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-12343","date":"2026-10-08","epss":0.00159,"percentile":0.0441}],"risk":0.07473,"urls":["https://access.redhat.com/security/cve/CVE-2025-12343","https://bugzilla.redhat.com/show_bug.cgi?id=2406533"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12343","description":"A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"25e5c6db21b416f6","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12343","versionConstraint":">= 6.1, < 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12343","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12343","cwe":"CWE-415","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-12343","date":"2026-10-08","epss":0.00159,"percentile":0.0441}],"risk":0.07473,"urls":["https://access.redhat.com/security/cve/CVE-2025-12343","https://bugzilla.redhat.com/show_bug.cgi?id=2406533"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12343","description":"A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"97989426551e99c7","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.8.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12343","versionConstraint":">= 6.1, < 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12343","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12343","cwe":"CWE-415","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-12343","date":"2026-10-08","epss":0.00159,"percentile":0.0441}],"risk":0.07473,"urls":["https://access.redhat.com/security/cve/CVE-2025-12343","https://bugzilla.redhat.com/show_bug.cgi?id=2406533"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12343","description":"A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"bc414f94a3468c9a","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12343","versionConstraint":">= 6.1, < 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12343","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12343","cwe":"CWE-415","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-12343","date":"2026-10-08","epss":0.00159,"percentile":0.0441}],"risk":0.07473,"urls":["https://access.redhat.com/security/cve/CVE-2025-12343","https://bugzilla.redhat.com/show_bug.cgi?id=2406533"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12343","description":"A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"a60284c46fc644ac","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:8.0.1-r1:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:8.0.1-r1:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@8.0.1-r1?arch=x86_64&distro=alpine-3.23.6&upstream=ffmpeg","type":"apk","version":"8.0.1-r1","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.9"},{"path":"/usr/lib/libswscale.so.9.1.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12343","versionConstraint":">= 6.1, < 8.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.0.1-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12343","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12343","cwe":"CWE-415","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-12343","date":"2026-10-08","epss":0.00159,"percentile":0.0441}],"risk":0.07473,"urls":["https://access.redhat.com/security/cve/CVE-2025-12343","https://bugzilla.redhat.com/show_bug.cgi?id=2406533"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12343","description":"A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"d033f6e836718f4b","cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-project:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:apk/alpine/alsa-lib@1.2.14-r2?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"1.2.14-r2","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/alsa"},{"path":"/etc/alsa/conf.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/aserver"},{"path":"/usr/lib"},{"path":"/usr/lib/libasound.so.2"},{"path":"/usr/lib/libasound.so.2.0.0"},{"path":"/usr/lib/libatopology.so.2"},{"path":"/usr/lib/libatopology.so.2.0.0"},{"path":"/usr/share"},{"path":"/usr/share/alsa"},{"path":"/usr/share/alsa/alsa.conf"},{"path":"/usr/share/alsa/cards"},{"path":"/usr/share/alsa/cards/AACI.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-MODEM.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-SPDMA.conf"},{"path":"/usr/share/alsa/cards/ATIIXP.conf"},{"path":"/usr/share/alsa/cards/AU8810.conf"},{"path":"/usr/share/alsa/cards/AU8820.conf"},{"path":"/usr/share/alsa/cards/AU8830.conf"},{"path":"/usr/share/alsa/cards/Audigy.conf"},{"path":"/usr/share/alsa/cards/Audigy2.conf"},{"path":"/usr/share/alsa/cards/Aureon51.conf"},{"path":"/usr/share/alsa/cards/Aureon71.conf"},{"path":"/usr/share/alsa/cards/CA0106.conf"},{"path":"/usr/share/alsa/cards/CMI8338-SWIEC.conf"},{"path":"/usr/share/alsa/cards/CMI8338.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC6.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC8.conf"},{"path":"/usr/share/alsa/cards/CMI8788.conf"},{"path":"/usr/share/alsa/cards/CS46xx.conf"},{"path":"/usr/share/alsa/cards/EMU10K1.conf"},{"path":"/usr/share/alsa/cards/EMU10K1X.conf"},{"path":"/usr/share/alsa/cards/ENS1370.conf"},{"path":"/usr/share/alsa/cards/ENS1371.conf"},{"path":"/usr/share/alsa/cards/ES1968.conf"},{"path":"/usr/share/alsa/cards/Echo_Echo3G.conf"},{"path":"/usr/share/alsa/cards/FM801.conf"},{"path":"/usr/share/alsa/cards/FWSpeakers.conf"},{"path":"/usr/share/alsa/cards/FireWave.conf"},{"path":"/usr/share/alsa/cards/GUS.conf"},{"path":"/usr/share/alsa/cards/HDA-Intel.conf"},{"path":"/usr/share/alsa/cards/HdmiLpeAudio.conf"},{"path":"/usr/share/alsa/cards/ICE1712.conf"},{"path":"/usr/share/alsa/cards/ICE1724.conf"},{"path":"/usr/share/alsa/cards/ICH-MODEM.conf"},{"path":"/usr/share/alsa/cards/ICH.conf"},{"path":"/usr/share/alsa/cards/ICH4.conf"},{"path":"/usr/share/alsa/cards/Loopback.conf"},{"path":"/usr/share/alsa/cards/Maestro3.conf"},{"path":"/usr/share/alsa/cards/NFORCE.conf"},{"path":"/usr/share/alsa/cards/PC-Speaker.conf"},{"path":"/usr/share/alsa/cards/PMac.conf"},{"path":"/usr/share/alsa/cards/PMacToonie.conf"},{"path":"/usr/share/alsa/cards/PS3.conf"},{"path":"/usr/share/alsa/cards/RME9636.conf"},{"path":"/usr/share/alsa/cards/RME9652.conf"},{"path":"/usr/share/alsa/cards/SB-XFi.conf"},{"path":"/usr/share/alsa/cards/SI7018.conf"},{"path":"/usr/share/alsa/cards/TRID4DWAVENX.conf"},{"path":"/usr/share/alsa/cards/USB-Audio.conf"},{"path":"/usr/share/alsa/cards/VIA686A.conf"},{"path":"/usr/share/alsa/cards/VIA8233.conf"},{"path":"/usr/share/alsa/cards/VIA8233A.conf"},{"path":"/usr/share/alsa/cards/VIA8237.conf"},{"path":"/usr/share/alsa/cards/VX222.conf"},{"path":"/usr/share/alsa/cards/VXPocket.conf"},{"path":"/usr/share/alsa/cards/VXPocket440.conf"},{"path":"/usr/share/alsa/cards/YMF744.conf"},{"path":"/usr/share/alsa/cards/aliases.conf"},{"path":"/usr/share/alsa/cards/pistachio-card.conf"},{"path":"/usr/share/alsa/cards/vc4-hdmi.conf"},{"path":"/usr/share/alsa/ctl"},{"path":"/usr/share/alsa/ctl/default.conf"},{"path":"/usr/share/alsa/pcm"},{"path":"/usr/share/alsa/pcm/center_lfe.conf"},{"path":"/usr/share/alsa/pcm/default.conf"},{"path":"/usr/share/alsa/pcm/dmix.conf"},{"path":"/usr/share/alsa/pcm/dpl.conf"},{"path":"/usr/share/alsa/pcm/dsnoop.conf"},{"path":"/usr/share/alsa/pcm/front.conf"},{"path":"/usr/share/alsa/pcm/hdmi.conf"},{"path":"/usr/share/alsa/pcm/iec958.conf"},{"path":"/usr/share/alsa/pcm/modem.conf"},{"path":"/usr/share/alsa/pcm/rear.conf"},{"path":"/usr/share/alsa/pcm/side.conf"},{"path":"/usr/share/alsa/pcm/surround21.conf"},{"path":"/usr/share/alsa/pcm/surround40.conf"},{"path":"/usr/share/alsa/pcm/surround41.conf"},{"path":"/usr/share/alsa/pcm/surround50.conf"},{"path":"/usr/share/alsa/pcm/surround51.conf"},{"path":"/usr/share/alsa/pcm/surround71.conf"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"alsa-lib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-96674","versionConstraint":"<= 1.2.16.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14:*:*:*:*:*:*:*"],"package":{"name":"alsa-lib","version":"1.2.14-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-96674","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96674","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-96674","date":"2026-10-08","epss":0.00115,"percentile":0.01438}],"risk":0.0552,"urls":["https://github.com/alsa-project/alsa-lib","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521","https://github.com/alsa-project/alsa-lib/pull/527","https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-integer-overflow-via-topology-file"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-96674","description":"alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application."},"relatedVulnerabilities":[]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59845","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59845","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59845","cwe":"CWE-390","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59845","cwe":"CWE-390","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59845","date":"2026-10-08","epss":0.00104,"percentile":0.00948}],"risk":0.055119999999999995,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59845","https://bugzilla.redhat.com/show_bug.cgi?id=2498178"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59845","description":"A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"d033f6e836718f4b","cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-project:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.14-r2:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.14-r2:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:apk/alpine/alsa-lib@1.2.14-r2?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"1.2.14-r2","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/alsa"},{"path":"/etc/alsa/conf.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/aserver"},{"path":"/usr/lib"},{"path":"/usr/lib/libasound.so.2"},{"path":"/usr/lib/libasound.so.2.0.0"},{"path":"/usr/lib/libatopology.so.2"},{"path":"/usr/lib/libatopology.so.2.0.0"},{"path":"/usr/share"},{"path":"/usr/share/alsa"},{"path":"/usr/share/alsa/alsa.conf"},{"path":"/usr/share/alsa/cards"},{"path":"/usr/share/alsa/cards/AACI.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-MODEM.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-SPDMA.conf"},{"path":"/usr/share/alsa/cards/ATIIXP.conf"},{"path":"/usr/share/alsa/cards/AU8810.conf"},{"path":"/usr/share/alsa/cards/AU8820.conf"},{"path":"/usr/share/alsa/cards/AU8830.conf"},{"path":"/usr/share/alsa/cards/Audigy.conf"},{"path":"/usr/share/alsa/cards/Audigy2.conf"},{"path":"/usr/share/alsa/cards/Aureon51.conf"},{"path":"/usr/share/alsa/cards/Aureon71.conf"},{"path":"/usr/share/alsa/cards/CA0106.conf"},{"path":"/usr/share/alsa/cards/CMI8338-SWIEC.conf"},{"path":"/usr/share/alsa/cards/CMI8338.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC6.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC8.conf"},{"path":"/usr/share/alsa/cards/CMI8788.conf"},{"path":"/usr/share/alsa/cards/CS46xx.conf"},{"path":"/usr/share/alsa/cards/EMU10K1.conf"},{"path":"/usr/share/alsa/cards/EMU10K1X.conf"},{"path":"/usr/share/alsa/cards/ENS1370.conf"},{"path":"/usr/share/alsa/cards/ENS1371.conf"},{"path":"/usr/share/alsa/cards/ES1968.conf"},{"path":"/usr/share/alsa/cards/Echo_Echo3G.conf"},{"path":"/usr/share/alsa/cards/FM801.conf"},{"path":"/usr/share/alsa/cards/FWSpeakers.conf"},{"path":"/usr/share/alsa/cards/FireWave.conf"},{"path":"/usr/share/alsa/cards/GUS.conf"},{"path":"/usr/share/alsa/cards/HDA-Intel.conf"},{"path":"/usr/share/alsa/cards/HdmiLpeAudio.conf"},{"path":"/usr/share/alsa/cards/ICE1712.conf"},{"path":"/usr/share/alsa/cards/ICE1724.conf"},{"path":"/usr/share/alsa/cards/ICH-MODEM.conf"},{"path":"/usr/share/alsa/cards/ICH.conf"},{"path":"/usr/share/alsa/cards/ICH4.conf"},{"path":"/usr/share/alsa/cards/Loopback.conf"},{"path":"/usr/share/alsa/cards/Maestro3.conf"},{"path":"/usr/share/alsa/cards/NFORCE.conf"},{"path":"/usr/share/alsa/cards/PC-Speaker.conf"},{"path":"/usr/share/alsa/cards/PMac.conf"},{"path":"/usr/share/alsa/cards/PMacToonie.conf"},{"path":"/usr/share/alsa/cards/PS3.conf"},{"path":"/usr/share/alsa/cards/RME9636.conf"},{"path":"/usr/share/alsa/cards/RME9652.conf"},{"path":"/usr/share/alsa/cards/SB-XFi.conf"},{"path":"/usr/share/alsa/cards/SI7018.conf"},{"path":"/usr/share/alsa/cards/TRID4DWAVENX.conf"},{"path":"/usr/share/alsa/cards/USB-Audio.conf"},{"path":"/usr/share/alsa/cards/VIA686A.conf"},{"path":"/usr/share/alsa/cards/VIA8233.conf"},{"path":"/usr/share/alsa/cards/VIA8233A.conf"},{"path":"/usr/share/alsa/cards/VIA8237.conf"},{"path":"/usr/share/alsa/cards/VX222.conf"},{"path":"/usr/share/alsa/cards/VXPocket.conf"},{"path":"/usr/share/alsa/cards/VXPocket440.conf"},{"path":"/usr/share/alsa/cards/YMF744.conf"},{"path":"/usr/share/alsa/cards/aliases.conf"},{"path":"/usr/share/alsa/cards/pistachio-card.conf"},{"path":"/usr/share/alsa/cards/vc4-hdmi.conf"},{"path":"/usr/share/alsa/ctl"},{"path":"/usr/share/alsa/ctl/default.conf"},{"path":"/usr/share/alsa/pcm"},{"path":"/usr/share/alsa/pcm/center_lfe.conf"},{"path":"/usr/share/alsa/pcm/default.conf"},{"path":"/usr/share/alsa/pcm/dmix.conf"},{"path":"/usr/share/alsa/pcm/dpl.conf"},{"path":"/usr/share/alsa/pcm/dsnoop.conf"},{"path":"/usr/share/alsa/pcm/front.conf"},{"path":"/usr/share/alsa/pcm/hdmi.conf"},{"path":"/usr/share/alsa/pcm/iec958.conf"},{"path":"/usr/share/alsa/pcm/modem.conf"},{"path":"/usr/share/alsa/pcm/rear.conf"},{"path":"/usr/share/alsa/pcm/side.conf"},{"path":"/usr/share/alsa/pcm/surround21.conf"},{"path":"/usr/share/alsa/pcm/surround40.conf"},{"path":"/usr/share/alsa/pcm/surround41.conf"},{"path":"/usr/share/alsa/pcm/surround50.conf"},{"path":"/usr/share/alsa/pcm/surround51.conf"},{"path":"/usr/share/alsa/pcm/surround71.conf"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"alsa-lib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-96675","versionConstraint":"<= 1.2.16.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14:*:*:*:*:*:*:*"],"package":{"name":"alsa-lib","version":"1.2.14-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-96675","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96675","cwe":"CWE-129","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-96675","date":"2026-10-08","epss":0.00111,"percentile":0.01223}],"risk":0.05022750000000001,"urls":["https://github.com/alsa-project/alsa-lib","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/pcm/pcm_multi.c#L1122-L1131","https://github.com/alsa-project/alsa-lib/pull/527","https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-denial-of-service-via-pcm-multi"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-96675","description":"alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort."},"relatedVulnerabilities":[]},{"artifact":{"id":"ce2351ba0f3ee938","cpes":["cpe:2.3:a:libssh:libssh:0.11.4-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.4-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"0.11.4-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59846","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.4:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59846","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59846","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59846","cwe":"CWE-77","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59846","date":"2026-10-08","epss":0.0012,"percentile":0.01657}],"risk":0.04139999999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59846","https://bugzilla.redhat.com/show_bug.cgi?id=2498179"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59846","description":"A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior."},"relatedVulnerabilities":[]},{"artifact":{"id":"09c24a4342b1cfdb","cpes":["cpe:2.3:a:python-software-foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python3:python:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python3:3.12.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.12.15-r0:*:*:*:*:*:*:*"],"name":"python3","purl":"pkg:apk/alpine/python3@3.12.15-r0?arch=x86_64&distro=alpine-3.23.6","type":"apk","version":"3.12.15-r0","language":"","licenses":["PSF-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/2to3"},{"path":"/usr/bin/2to3-3.12"},{"path":"/usr/bin/pydoc3"},{"path":"/usr/bin/pydoc3.12"},{"path":"/usr/bin/python"},{"path":"/usr/bin/python3"},{"path":"/usr/bin/python3.12"},{"path":"/usr/include"},{"path":"/usr/include/python3.12"},{"path":"/usr/include/python3.12/pyconfig.h"},{"path":"/usr/lib"},{"path":"/usr/lib/libpython3.12.so.1.0"},{"path":"/usr/lib/libpython3.so"},{"path":"/usr/lib/python3.12"},{"path":"/usr/lib/python3.12/EXTERNALLY-MANAGED"},{"path":"/usr/lib/python3.12/LICENSE.txt"},{"path":"/usr/lib/python3.12/__future__.py"},{"path":"/usr/lib/python3.12/__hello__.py"},{"path":"/usr/lib/python3.12/_aix_support.py"},{"path":"/usr/lib/python3.12/_collections_abc.py"},{"path":"/usr/lib/python3.12/_compat_pickle.py"},{"path":"/usr/lib/python3.12/_compression.py"},{"path":"/usr/lib/python3.12/_markupbase.py"},{"path":"/usr/lib/python3.12/_osx_support.py"},{"path":"/usr/lib/python3.12/_py_abc.py"},{"path":"/usr/lib/python3.12/_pydatetime.py"},{"path":"/usr/lib/python3.12/_pydecimal.py"},{"path":"/usr/lib/python3.12/_pyio.py"},{"path":"/usr/lib/python3.12/_pylong.py"},{"path":"/usr/lib/python3.12/_sitebuiltins.py"},{"path":"/usr/lib/python3.12/_strptime.py"},{"path":"/usr/lib/python3.12/_sysconfigdata__linux_x86_64-linux-musl.py"},{"path":"/usr/lib/python3.12/_threading_local.py"},{"path":"/usr/lib/python3.12/_weakrefset.py"},{"path":"/usr/lib/python3.12/abc.py"},{"path":"/usr/lib/python3.12/aifc.py"},{"path":"/usr/lib/python3.12/antigravity.py"},{"path":"/usr/lib/python3.12/argparse.py"},{"path":"/usr/lib/python3.12/ast.py"},{"path":"/usr/lib/python3.12/base64.py"},{"path":"/usr/lib/python3.12/bdb.py"},{"path":"/usr/lib/python3.12/bisect.py"},{"path":"/usr/lib/python3.12/bz2.py"},{"path":"/usr/lib/python3.12/cProfile.py"},{"path":"/usr/lib/python3.12/calendar.py"},{"path":"/usr/lib/python3.12/cgi.py"},{"path":"/usr/lib/python3.12/cgitb.py"},{"path":"/usr/lib/python3.12/chunk.py"},{"path":"/usr/lib/python3.12/cmd.py"},{"path":"/usr/lib/python3.12/code.py"},{"path":"/usr/lib/python3.12/codecs.py"},{"path":"/usr/lib/python3.12/codeop.py"},{"path":"/usr/lib/python3.12/colorsys.py"},{"path":"/usr/lib/python3.12/compileall.py"},{"path":"/usr/lib/python3.12/configparser.py"},{"path":"/usr/lib/python3.12/contextlib.py"},{"path":"/usr/lib/python3.12/contextvars.py"},{"path":"/usr/lib/python3.12/copy.py"},{"path":"/usr/lib/python3.12/copyreg.py"},{"path":"/usr/lib/python3.12/crypt.py"},{"path":"/usr/lib/python3.12/csv.py"},{"path":"/usr/lib/python3.12/dataclasses.py"},{"path":"/usr/lib/python3.12/datetime.py"},{"path":"/usr/lib/python3.12/decimal.py"},{"path":"/usr/lib/python3.12/difflib.py"},{"path":"/usr/lib/python3.12/dis.py"},{"path":"/usr/lib/python3.12/doctest.py"},{"path":"/usr/lib/python3.12/enum.py"},{"path":"/usr/lib/python3.12/filecmp.py"},{"path":"/usr/lib/python3.12/fileinput.py"},{"path":"/usr/lib/python3.12/fnmatch.py"},{"path":"/usr/lib/python3.12/fractions.py"},{"path":"/usr/lib/python3.12/ftplib.py"},{"path":"/usr/lib/python3.12/functools.py"},{"path":"/usr/lib/python3.12/genericpath.py"},{"path":"/usr/lib/python3.12/getopt.py"},{"path":"/usr/lib/python3.12/getpass.py"},{"path":"/usr/lib/python3.12/gettext.py"},{"path":"/usr/lib/python3.12/glob.py"},{"path":"/usr/lib/python3.12/graphlib.py"},{"path":"/usr/lib/python3.12/gzip.py"},{"path":"/usr/lib/python3.12/hashlib.py"},{"path":"/usr/lib/python3.12/heapq.py"},{"path":"/usr/lib/python3.12/hmac.py"},{"path":"/usr/lib/python3.12/imaplib.py"},{"path":"/usr/lib/python3.12/imghdr.py"},{"path":"/usr/lib/python3.12/inspect.py"},{"path":"/usr/lib/python3.12/io.py"},{"path":"/usr/lib/python3.12/ipaddress.py"},{"path":"/usr/lib/python3.12/keyword.py"},{"path":"/usr/lib/python3.12/linecache.py"},{"path":"/usr/lib/python3.12/locale.py"},{"path":"/usr/lib/python3.12/lzma.py"},{"path":"/usr/lib/python3.12/mailbox.py"},{"path":"/usr/lib/python3.12/mailcap.py"},{"path":"/usr/lib/python3.12/mimetypes.py"},{"path":"/usr/lib/python3.12/modulefinder.py"},{"path":"/usr/lib/python3.12/netrc.py"},{"path":"/usr/lib/python3.12/nntplib.py"},{"path":"/usr/lib/python3.12/ntpath.py"},{"path":"/usr/lib/python3.12/nturl2path.py"},{"path":"/usr/lib/python3.12/numbers.py"},{"path":"/usr/lib/python3.12/opcode.py"},{"path":"/usr/lib/python3.12/operator.py"},{"path":"/usr/lib/python3.12/optparse.py"},{"path":"/usr/lib/python3.12/os.py"},{"path":"/usr/lib/python3.12/pathlib.py"},{"path":"/usr/lib/python3.12/pdb.py"},{"path":"/usr/lib/python3.12/pickle.py"},{"path":"/usr/lib/python3.12/pickletools.py"},{"path":"/usr/lib/python3.12/pipes.py"},{"path":"/usr/lib/python3.12/pkgutil.py"},{"path":"/usr/lib/python3.12/platform.py"},{"path":"/usr/lib/python3.12/plistlib.py"},{"path":"/usr/lib/python3.12/poplib.py"},{"path":"/usr/lib/python3.12/posixpath.py"},{"path":"/usr/lib/python3.12/pprint.py"},{"path":"/usr/lib/python3.12/profile.py"},{"path":"/usr/lib/python3.12/pstats.py"},{"path":"/usr/lib/python3.12/pty.py"},{"path":"/usr/lib/python3.12/py_compile.py"},{"path":"/usr/lib/python3.12/pyclbr.py"},{"path":"/usr/lib/python3.12/pydoc.py"},{"path":"/usr/lib/python3.12/queue.py"},{"path":"/usr/lib/python3.12/quopri.py"},{"path":"/usr/lib/python3.12/random.py"},{"path":"/usr/lib/python3.12/reprlib.py"},{"path":"/usr/lib/python3.12/rlcompleter.py"},{"path":"/usr/lib/python3.12/runpy.py"},{"path":"/usr/lib/python3.12/sched.py"},{"path":"/usr/lib/python3.12/secrets.py"},{"path":"/usr/lib/python3.12/selectors.py"},{"path":"/usr/lib/python3.12/shelve.py"},{"path":"/usr/lib/python3.12/shlex.py"},{"path":"/usr/lib/python3.12/shutil.py"},{"path":"/usr/lib/python3.12/signal.py"},{"path":"/usr/lib/python3.12/site.py"},{"path":"/usr/lib/python3.12/smtplib.py"},{"path":"/usr/lib/python3.12/sndhdr.py"},{"path":"/usr/lib/python3.12/socket.py"},{"path":"/usr/lib/python3.12/socketserver.py"},{"path":"/usr/lib/python3.12/sre_compile.py"},{"path":"/usr/lib/python3.12/sre_constants.py"},{"path":"/usr/lib/python3.12/sre_parse.py"},{"path":"/usr/lib/python3.12/ssl.py"},{"path":"/usr/lib/python3.12/stat.py"},{"path":"/usr/lib/python3.12/statistics.py"},{"path":"/usr/lib/python3.12/string.py"},{"path":"/usr/lib/python3.12/stringprep.py"},{"path":"/usr/lib/python3.12/struct.py"},{"path":"/usr/lib/python3.12/subprocess.py"},{"path":"/usr/lib/python3.12/sunau.py"},{"path":"/usr/lib/python3.12/symtable.py"},{"path":"/usr/lib/python3.12/sysconfig.py"},{"path":"/usr/lib/python3.12/tabnanny.py"},{"path":"/usr/lib/python3.12/tarfile.py"},{"path":"/usr/lib/python3.12/telnetlib.py"},{"path":"/usr/lib/python3.12/tempfile.py"},{"path":"/usr/lib/python3.12/textwrap.py"},{"path":"/usr/lib/python3.12/this.py"},{"path":"/usr/lib/python3.12/threading.py"},{"path":"/usr/lib/python3.12/timeit.py"},{"path":"/usr/lib/python3.12/token.py"},{"path":"/usr/lib/python3.12/tokenize.py"},{"path":"/usr/lib/python3.12/trace.py"},{"path":"/usr/lib/python3.12/traceback.py"},{"path":"/usr/lib/python3.12/tracemalloc.py"},{"path":"/usr/lib/python3.12/tty.py"},{"path":"/usr/lib/python3.12/turtle.py"},{"path":"/usr/lib/python3.12/types.py"},{"path":"/usr/lib/python3.12/typing.py"},{"path":"/usr/lib/python3.12/uu.py"},{"path":"/usr/lib/python3.12/uuid.py"},{"path":"/usr/lib/python3.12/warnings.py"},{"path":"/usr/lib/python3.12/wave.py"},{"path":"/usr/lib/python3.12/weakref.py"},{"path":"/usr/lib/python3.12/webbrowser.py"},{"path":"/usr/lib/python3.12/xdrlib.py"},{"path":"/usr/lib/python3.12/zipapp.py"},{"path":"/usr/lib/python3.12/zipimport.py"},{"path":"/usr/lib/python3.12/__phello__"},{"path":"/usr/lib/python3.12/__phello__/__init__.py"},{"path":"/usr/lib/python3.12/__phello__/spam.py"},{"path":"/usr/lib/python3.12/asyncio"},{"path":"/usr/lib/python3.12/asyncio/__init__.py"},{"path":"/usr/lib/python3.12/asyncio/__main__.py"},{"path":"/usr/lib/python3.12/asyncio/base_events.py"},{"path":"/usr/lib/python3.12/asyncio/base_futures.py"},{"path":"/usr/lib/python3.12/asyncio/base_subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/base_tasks.py"},{"path":"/usr/lib/python3.12/asyncio/constants.py"},{"path":"/usr/lib/python3.12/asyncio/coroutines.py"},{"path":"/usr/lib/python3.12/asyncio/events.py"},{"path":"/usr/lib/python3.12/asyncio/exceptions.py"},{"path":"/usr/lib/python3.12/asyncio/format_helpers.py"},{"path":"/usr/lib/python3.12/asyncio/futures.py"},{"path":"/usr/lib/python3.12/asyncio/locks.py"},{"path":"/usr/lib/python3.12/asyncio/log.py"},{"path":"/usr/lib/python3.12/asyncio/mixins.py"},{"path":"/usr/lib/python3.12/asyncio/proactor_events.py"},{"path":"/usr/lib/python3.12/asyncio/protocols.py"},{"path":"/usr/lib/python3.12/asyncio/queues.py"},{"path":"/usr/lib/python3.12/asyncio/runners.py"},{"path":"/usr/lib/python3.12/asyncio/selector_events.py"},{"path":"/usr/lib/python3.12/asyncio/sslproto.py"},{"path":"/usr/lib/python3.12/asyncio/staggered.py"},{"path":"/usr/lib/python3.12/asyncio/streams.py"},{"path":"/usr/lib/python3.12/asyncio/subprocess.py"},{"path":"/usr/lib/python3.12/asyncio/taskgroups.py"},{"path":"/usr/lib/python3.12/asyncio/tasks.py"},{"path":"/usr/lib/python3.12/asyncio/threads.py"},{"path":"/usr/lib/python3.12/asyncio/timeouts.py"},{"path":"/usr/lib/python3.12/asyncio/transports.py"},{"path":"/usr/lib/python3.12/asyncio/trsock.py"},{"path":"/usr/lib/python3.12/asyncio/unix_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_events.py"},{"path":"/usr/lib/python3.12/asyncio/windows_utils.py"},{"path":"/usr/lib/python3.12/collections"},{"path":"/usr/lib/python3.12/collections/__init__.py"},{"path":"/usr/lib/python3.12/collections/abc.py"},{"path":"/usr/lib/python3.12/concurrent"},{"path":"/usr/lib/python3.12/concurrent/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures"},{"path":"/usr/lib/python3.12/concurrent/futures/__init__.py"},{"path":"/usr/lib/python3.12/concurrent/futures/_base.py"},{"path":"/usr/lib/python3.12/concurrent/futures/process.py"},{"path":"/usr/lib/python3.12/concurrent/futures/thread.py"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Makefile"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.bootstrap"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.local"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/Setup.stdlib"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/config.c.in"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/install-sh"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/makesetup"},{"path":"/usr/lib/python3.12/config-3.12-x86_64-linux-musl/python-config.py"},{"path":"/usr/lib/python3.12/ctypes"},{"path":"/usr/lib/python3.12/ctypes/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/_aix.py"},{"path":"/usr/lib/python3.12/ctypes/_endian.py"},{"path":"/usr/lib/python3.12/ctypes/util.py"},{"path":"/usr/lib/python3.12/ctypes/wintypes.py"},{"path":"/usr/lib/python3.12/ctypes/macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/README.ctypes"},{"path":"/usr/lib/python3.12/ctypes/macholib/__init__.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dyld.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/dylib.py"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib"},{"path":"/usr/lib/python3.12/ctypes/macholib/fetch_macholib.bat"},{"path":"/usr/lib/python3.12/ctypes/macholib/framework.py"},{"path":"/usr/lib/python3.12/curses"},{"path":"/usr/lib/python3.12/curses/__init__.py"},{"path":"/usr/lib/python3.12/curses/ascii.py"},{"path":"/usr/lib/python3.12/curses/has_key.py"},{"path":"/usr/lib/python3.12/curses/panel.py"},{"path":"/usr/lib/python3.12/curses/textpad.py"},{"path":"/usr/lib/python3.12/dbm"},{"path":"/usr/lib/python3.12/dbm/__init__.py"},{"path":"/usr/lib/python3.12/dbm/dumb.py"},{"path":"/usr/lib/python3.12/dbm/gnu.py"},{"path":"/usr/lib/python3.12/dbm/ndbm.py"},{"path":"/usr/lib/python3.12/email"},{"path":"/usr/lib/python3.12/email/__init__.py"},{"path":"/usr/lib/python3.12/email/_encoded_words.py"},{"path":"/usr/lib/python3.12/email/_header_value_parser.py"},{"path":"/usr/lib/python3.12/email/_parseaddr.py"},{"path":"/usr/lib/python3.12/email/_policybase.py"},{"path":"/usr/lib/python3.12/email/architecture.rst"},{"path":"/usr/lib/python3.12/email/base64mime.py"},{"path":"/usr/lib/python3.12/email/charset.py"},{"path":"/usr/lib/python3.12/email/contentmanager.py"},{"path":"/usr/lib/python3.12/email/encoders.py"},{"path":"/usr/lib/python3.12/email/errors.py"},{"path":"/usr/lib/python3.12/email/feedparser.py"},{"path":"/usr/lib/python3.12/email/generator.py"},{"path":"/usr/lib/python3.12/email/header.py"},{"path":"/usr/lib/python3.12/email/headerregistry.py"},{"path":"/usr/lib/python3.12/email/iterators.py"},{"path":"/usr/lib/python3.12/email/message.py"},{"path":"/usr/lib/python3.12/email/parser.py"},{"path":"/usr/lib/python3.12/email/policy.py"},{"path":"/usr/lib/python3.12/email/quoprimime.py"},{"path":"/usr/lib/python3.12/email/utils.py"},{"path":"/usr/lib/python3.12/email/mime"},{"path":"/usr/lib/python3.12/email/mime/__init__.py"},{"path":"/usr/lib/python3.12/email/mime/application.py"},{"path":"/usr/lib/python3.12/email/mime/audio.py"},{"path":"/usr/lib/python3.12/email/mime/base.py"},{"path":"/usr/lib/python3.12/email/mime/image.py"},{"path":"/usr/lib/python3.12/email/mime/message.py"},{"path":"/usr/lib/python3.12/email/mime/multipart.py"},{"path":"/usr/lib/python3.12/email/mime/nonmultipart.py"},{"path":"/usr/lib/python3.12/email/mime/text.py"},{"path":"/usr/lib/python3.12/encodings"},{"path":"/usr/lib/python3.12/encodings/__init__.py"},{"path":"/usr/lib/python3.12/encodings/aliases.py"},{"path":"/usr/lib/python3.12/encodings/ascii.py"},{"path":"/usr/lib/python3.12/encodings/base64_codec.py"},{"path":"/usr/lib/python3.12/encodings/big5.py"},{"path":"/usr/lib/python3.12/encodings/big5hkscs.py"},{"path":"/usr/lib/python3.12/encodings/bz2_codec.py"},{"path":"/usr/lib/python3.12/encodings/charmap.py"},{"path":"/usr/lib/python3.12/encodings/cp037.py"},{"path":"/usr/lib/python3.12/encodings/cp1006.py"},{"path":"/usr/lib/python3.12/encodings/cp1026.py"},{"path":"/usr/lib/python3.12/encodings/cp1125.py"},{"path":"/usr/lib/python3.12/encodings/cp1140.py"},{"path":"/usr/lib/python3.12/encodings/cp1250.py"},{"path":"/usr/lib/python3.12/encodings/cp1251.py"},{"path":"/usr/lib/python3.12/encodings/cp1252.py"},{"path":"/usr/lib/python3.12/encodings/cp1253.py"},{"path":"/usr/lib/python3.12/encodings/cp1254.py"},{"path":"/usr/lib/python3.12/encodings/cp1255.py"},{"path":"/usr/lib/python3.12/encodings/cp1256.py"},{"path":"/usr/lib/python3.12/encodings/cp1257.py"},{"path":"/usr/lib/python3.12/encodings/cp1258.py"},{"path":"/usr/lib/python3.12/encodings/cp273.py"},{"path":"/usr/lib/python3.12/encodings/cp424.py"},{"path":"/usr/lib/python3.12/encodings/cp437.py"},{"path":"/usr/lib/python3.12/encodings/cp500.py"},{"path":"/usr/lib/python3.12/encodings/cp720.py"},{"path":"/usr/lib/python3.12/encodings/cp737.py"},{"path":"/usr/lib/python3.12/encodings/cp775.py"},{"path":"/usr/lib/python3.12/encodings/cp850.py"},{"path":"/usr/lib/python3.12/encodings/cp852.py"},{"path":"/usr/lib/python3.12/encodings/cp855.py"},{"path":"/usr/lib/python3.12/encodings/cp856.py"},{"path":"/usr/lib/python3.12/encodings/cp857.py"},{"path":"/usr/lib/python3.12/encodings/cp858.py"},{"path":"/usr/lib/python3.12/encodings/cp860.py"},{"path":"/usr/lib/python3.12/encodings/cp861.py"},{"path":"/usr/lib/python3.12/encodings/cp862.py"},{"path":"/usr/lib/python3.12/encodings/cp863.py"},{"path":"/usr/lib/python3.12/encodings/cp864.py"},{"path":"/usr/lib/python3.12/encodings/cp865.py"},{"path":"/usr/lib/python3.12/encodings/cp866.py"},{"path":"/usr/lib/python3.12/encodings/cp869.py"},{"path":"/usr/lib/python3.12/encodings/cp874.py"},{"path":"/usr/lib/python3.12/encodings/cp875.py"},{"path":"/usr/lib/python3.12/encodings/cp932.py"},{"path":"/usr/lib/python3.12/encodings/cp949.py"},{"path":"/usr/lib/python3.12/encodings/cp950.py"},{"path":"/usr/lib/python3.12/encodings/euc_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/euc_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/euc_jp.py"},{"path":"/usr/lib/python3.12/encodings/euc_kr.py"},{"path":"/usr/lib/python3.12/encodings/gb18030.py"},{"path":"/usr/lib/python3.12/encodings/gb2312.py"},{"path":"/usr/lib/python3.12/encodings/gbk.py"},{"path":"/usr/lib/python3.12/encodings/hex_codec.py"},{"path":"/usr/lib/python3.12/encodings/hp_roman8.py"},{"path":"/usr/lib/python3.12/encodings/hz.py"},{"path":"/usr/lib/python3.12/encodings/idna.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_1.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_2004.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_3.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_jp_ext.py"},{"path":"/usr/lib/python3.12/encodings/iso2022_kr.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_1.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_10.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_11.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_13.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_14.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_15.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_16.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_2.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_3.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_4.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_5.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_6.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_7.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_8.py"},{"path":"/usr/lib/python3.12/encodings/iso8859_9.py"},{"path":"/usr/lib/python3.12/encodings/johab.py"},{"path":"/usr/lib/python3.12/encodings/koi8_r.py"},{"path":"/usr/lib/python3.12/encodings/koi8_t.py"},{"path":"/usr/lib/python3.12/encodings/koi8_u.py"},{"path":"/usr/lib/python3.12/encodings/kz1048.py"},{"path":"/usr/lib/python3.12/encodings/latin_1.py"},{"path":"/usr/lib/python3.12/encodings/mac_arabic.py"},{"path":"/usr/lib/python3.12/encodings/mac_croatian.py"},{"path":"/usr/lib/python3.12/encodings/mac_cyrillic.py"},{"path":"/usr/lib/python3.12/encodings/mac_farsi.py"},{"path":"/usr/lib/python3.12/encodings/mac_greek.py"},{"path":"/usr/lib/python3.12/encodings/mac_iceland.py"},{"path":"/usr/lib/python3.12/encodings/mac_latin2.py"},{"path":"/usr/lib/python3.12/encodings/mac_roman.py"},{"path":"/usr/lib/python3.12/encodings/mac_romanian.py"},{"path":"/usr/lib/python3.12/encodings/mac_turkish.py"},{"path":"/usr/lib/python3.12/encodings/mbcs.py"},{"path":"/usr/lib/python3.12/encodings/oem.py"},{"path":"/usr/lib/python3.12/encodings/palmos.py"},{"path":"/usr/lib/python3.12/encodings/ptcp154.py"},{"path":"/usr/lib/python3.12/encodings/punycode.py"},{"path":"/usr/lib/python3.12/encodings/quopri_codec.py"},{"path":"/usr/lib/python3.12/encodings/raw_unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/rot_13.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis.py"},{"path":"/usr/lib/python3.12/encodings/shift_jis_2004.py"},{"path":"/usr/lib/python3.12/encodings/shift_jisx0213.py"},{"path":"/usr/lib/python3.12/encodings/tis_620.py"},{"path":"/usr/lib/python3.12/encodings/undefined.py"},{"path":"/usr/lib/python3.12/encodings/unicode_escape.py"},{"path":"/usr/lib/python3.12/encodings/utf_16.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_16_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_32.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_be.py"},{"path":"/usr/lib/python3.12/encodings/utf_32_le.py"},{"path":"/usr/lib/python3.12/encodings/utf_7.py"},{"path":"/usr/lib/python3.12/encodings/utf_8.py"},{"path":"/usr/lib/python3.12/encodings/utf_8_sig.py"},{"path":"/usr/lib/python3.12/encodings/uu_codec.py"},{"path":"/usr/lib/python3.12/encodings/zlib_codec.py"},{"path":"/usr/lib/python3.12/ensurepip"},{"path":"/usr/lib/python3.12/ensurepip/__init__.py"},{"path":"/usr/lib/python3.12/ensurepip/__main__.py"},{"path":"/usr/lib/python3.12/ensurepip/_uninstall.py"},{"path":"/usr/lib/python3.12/ensurepip/_bundled"},{"path":"/usr/lib/python3.12/ensurepip/_bundled/pip-25.0.1-py3-none-any.whl"},{"path":"/usr/lib/python3.12/html"},{"path":"/usr/lib/python3.12/html/__init__.py"},{"path":"/usr/lib/python3.12/html/entities.py"},{"path":"/usr/lib/python3.12/html/parser.py"},{"path":"/usr/lib/python3.12/http"},{"path":"/usr/lib/python3.12/http/__init__.py"},{"path":"/usr/lib/python3.12/http/client.py"},{"path":"/usr/lib/python3.12/http/cookiejar.py"},{"path":"/usr/lib/python3.12/http/cookies.py"},{"path":"/usr/lib/python3.12/http/server.py"},{"path":"/usr/lib/python3.12/importlib"},{"path":"/usr/lib/python3.12/importlib/__init__.py"},{"path":"/usr/lib/python3.12/importlib/_abc.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap.py"},{"path":"/usr/lib/python3.12/importlib/_bootstrap_external.py"},{"path":"/usr/lib/python3.12/importlib/abc.py"},{"path":"/usr/lib/python3.12/importlib/machinery.py"},{"path":"/usr/lib/python3.12/importlib/readers.py"},{"path":"/usr/lib/python3.12/importlib/simple.py"},{"path":"/usr/lib/python3.12/importlib/util.py"},{"path":"/usr/lib/python3.12/importlib/metadata"},{"path":"/usr/lib/python3.12/importlib/metadata/__init__.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_collections.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_functools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_meta.py"},{"path":"/usr/lib/python3.12/importlib/metadata/_text.py"},{"path":"/usr/lib/python3.12/importlib/resources"},{"path":"/usr/lib/python3.12/importlib/resources/__init__.py"},{"path":"/usr/lib/python3.12/importlib/resources/_adapters.py"},{"path":"/usr/lib/python3.12/importlib/resources/_common.py"},{"path":"/usr/lib/python3.12/importlib/resources/_itertools.py"},{"path":"/usr/lib/python3.12/importlib/resources/_legacy.py"},{"path":"/usr/lib/python3.12/importlib/resources/abc.py"},{"path":"/usr/lib/python3.12/importlib/resources/readers.py"},{"path":"/usr/lib/python3.12/importlib/resources/simple.py"},{"path":"/usr/lib/python3.12/json"},{"path":"/usr/lib/python3.12/json/__init__.py"},{"path":"/usr/lib/python3.12/json/decoder.py"},{"path":"/usr/lib/python3.12/json/encoder.py"},{"path":"/usr/lib/python3.12/json/scanner.py"},{"path":"/usr/lib/python3.12/json/tool.py"},{"path":"/usr/lib/python3.12/lib-dynload"},{"path":"/usr/lib/python3.12/lib-dynload/_asyncio.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bisect.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_blake2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_bz2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_cn.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_hk.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_iso2022.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_jp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_kr.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_codecs_tw.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_contextvars.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_crypt.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_csv.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ctypes_test.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_curses_panel.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_datetime.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_dbm.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_decimal.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_elementtree.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_hashlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_heapq.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_json.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lsprof.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_lzma.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_md5.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multibytecodec.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_multiprocessing.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_opcode.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_pickle.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixshmem.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_posixsubprocess.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_queue.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_random.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha1.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha2.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sha3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_socket.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_sqlite3.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_ssl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_statistics.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_struct.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testbuffer.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testclinic.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testimportmultiple.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testinternalcapi.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testmultiphase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_testsinglephase.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxinterpchannels.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxsubinterpreters.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_xxtestfuzz.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/_zoneinfo.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/array.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/audioop.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/binascii.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/cmath.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/fcntl.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/grp.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/math.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/mmap.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/ossaudiodev.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/pyexpat.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/readline.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/resource.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/select.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/spwd.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/syslog.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/termios.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/unicodedata.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxlimited_35.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/xxsubtype.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib-dynload/zlib.cpython-312-x86_64-linux-musl.so"},{"path":"/usr/lib/python3.12/lib2to3"},{"path":"/usr/lib/python3.12/lib2to3/Grammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/Grammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar.txt"},{"path":"/usr/lib/python3.12/lib2to3/PatternGrammar3.12.15.final.0.pickle"},{"path":"/usr/lib/python3.12/lib2to3/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/__main__.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_matcher.py"},{"path":"/usr/lib/python3.12/lib2to3/btm_utils.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_base.py"},{"path":"/usr/lib/python3.12/lib2to3/fixer_util.py"},{"path":"/usr/lib/python3.12/lib2to3/main.py"},{"path":"/usr/lib/python3.12/lib2to3/patcomp.py"},{"path":"/usr/lib/python3.12/lib2to3/pygram.py"},{"path":"/usr/lib/python3.12/lib2to3/pytree.py"},{"path":"/usr/lib/python3.12/lib2to3/refactor.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes"},{"path":"/usr/lib/python3.12/lib2to3/fixes/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_apply.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_asserts.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_basestring.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_buffer.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_dict.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_except.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exec.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_execfile.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_exitfunc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_filter.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_funcattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_future.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_getcwdu.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_has_key.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_idioms.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_import.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_imports2.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_intern.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_isinstance.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_itertools_imports.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_long.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_map.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_metaclass.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_methodattrs.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ne.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_next.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_nonzero.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_numliterals.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_operator.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_paren.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_print.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raise.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_raw_input.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reduce.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_reload.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_renames.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_repr.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_set_literal.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_standarderror.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_sys_exc.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_throw.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_tuple_params.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_types.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_unicode.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_urllib.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_ws_comma.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xrange.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_xreadlines.py"},{"path":"/usr/lib/python3.12/lib2to3/fixes/fix_zip.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/__init__.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/conv.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/driver.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/grammar.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/literals.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/parse.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/pgen.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/token.py"},{"path":"/usr/lib/python3.12/lib2to3/pgen2/tokenize.py"},{"path":"/usr/lib/python3.12/logging"},{"path":"/usr/lib/python3.12/logging/__init__.py"},{"path":"/usr/lib/python3.12/logging/config.py"},{"path":"/usr/lib/python3.12/logging/handlers.py"},{"path":"/usr/lib/python3.12/multiprocessing"},{"path":"/usr/lib/python3.12/multiprocessing/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/connection.py"},{"path":"/usr/lib/python3.12/multiprocessing/context.py"},{"path":"/usr/lib/python3.12/multiprocessing/forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/heap.py"},{"path":"/usr/lib/python3.12/multiprocessing/managers.py"},{"path":"/usr/lib/python3.12/multiprocessing/pool.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_fork.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_forkserver.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_posix.py"},{"path":"/usr/lib/python3.12/multiprocessing/popen_spawn_win32.py"},{"path":"/usr/lib/python3.12/multiprocessing/process.py"},{"path":"/usr/lib/python3.12/multiprocessing/queues.py"},{"path":"/usr/lib/python3.12/multiprocessing/reduction.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_sharer.py"},{"path":"/usr/lib/python3.12/multiprocessing/resource_tracker.py"},{"path":"/usr/lib/python3.12/multiprocessing/shared_memory.py"},{"path":"/usr/lib/python3.12/multiprocessing/sharedctypes.py"},{"path":"/usr/lib/python3.12/multiprocessing/spawn.py"},{"path":"/usr/lib/python3.12/multiprocessing/synchronize.py"},{"path":"/usr/lib/python3.12/multiprocessing/util.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/__init__.py"},{"path":"/usr/lib/python3.12/multiprocessing/dummy/connection.py"},{"path":"/usr/lib/python3.12/pydoc_data"},{"path":"/usr/lib/python3.12/pydoc_data/__init__.py"},{"path":"/usr/lib/python3.12/pydoc_data/_pydoc.css"},{"path":"/usr/lib/python3.12/pydoc_data/topics.py"},{"path":"/usr/lib/python3.12/re"},{"path":"/usr/lib/python3.12/re/__init__.py"},{"path":"/usr/lib/python3.12/re/_casefix.py"},{"path":"/usr/lib/python3.12/re/_compiler.py"},{"path":"/usr/lib/python3.12/re/_constants.py"},{"path":"/usr/lib/python3.12/re/_parser.py"},{"path":"/usr/lib/python3.12/site-packages"},{"path":"/usr/lib/python3.12/site-packages/README.txt"},{"path":"/usr/lib/python3.12/sqlite3"},{"path":"/usr/lib/python3.12/sqlite3/__init__.py"},{"path":"/usr/lib/python3.12/sqlite3/__main__.py"},{"path":"/usr/lib/python3.12/sqlite3/dbapi2.py"},{"path":"/usr/lib/python3.12/sqlite3/dump.py"},{"path":"/usr/lib/python3.12/tomllib"},{"path":"/usr/lib/python3.12/tomllib/__init__.py"},{"path":"/usr/lib/python3.12/tomllib/_parser.py"},{"path":"/usr/lib/python3.12/tomllib/_re.py"},{"path":"/usr/lib/python3.12/tomllib/_types.py"},{"path":"/usr/lib/python3.12/turtledemo"},{"path":"/usr/lib/python3.12/turtledemo/__init__.py"},{"path":"/usr/lib/python3.12/turtledemo/__main__.py"},{"path":"/usr/lib/python3.12/turtledemo/bytedesign.py"},{"path":"/usr/lib/python3.12/turtledemo/chaos.py"},{"path":"/usr/lib/python3.12/turtledemo/clock.py"},{"path":"/usr/lib/python3.12/turtledemo/colormixer.py"},{"path":"/usr/lib/python3.12/turtledemo/forest.py"},{"path":"/usr/lib/python3.12/turtledemo/fractalcurves.py"},{"path":"/usr/lib/python3.12/turtledemo/lindenmayer.py"},{"path":"/usr/lib/python3.12/turtledemo/minimal_hanoi.py"},{"path":"/usr/lib/python3.12/turtledemo/nim.py"},{"path":"/usr/lib/python3.12/turtledemo/paint.py"},{"path":"/usr/lib/python3.12/turtledemo/peace.py"},{"path":"/usr/lib/python3.12/turtledemo/penrose.py"},{"path":"/usr/lib/python3.12/turtledemo/planet_and_moon.py"},{"path":"/usr/lib/python3.12/turtledemo/rosette.py"},{"path":"/usr/lib/python3.12/turtledemo/round_dance.py"},{"path":"/usr/lib/python3.12/turtledemo/sorting_animate.py"},{"path":"/usr/lib/python3.12/turtledemo/tree.py"},{"path":"/usr/lib/python3.12/turtledemo/turtle.cfg"},{"path":"/usr/lib/python3.12/turtledemo/two_canvases.py"},{"path":"/usr/lib/python3.12/turtledemo/yinyang.py"},{"path":"/usr/lib/python3.12/unittest"},{"path":"/usr/lib/python3.12/unittest/__init__.py"},{"path":"/usr/lib/python3.12/unittest/__main__.py"},{"path":"/usr/lib/python3.12/unittest/_log.py"},{"path":"/usr/lib/python3.12/unittest/async_case.py"},{"path":"/usr/lib/python3.12/unittest/case.py"},{"path":"/usr/lib/python3.12/unittest/loader.py"},{"path":"/usr/lib/python3.12/unittest/main.py"},{"path":"/usr/lib/python3.12/unittest/mock.py"},{"path":"/usr/lib/python3.12/unittest/result.py"},{"path":"/usr/lib/python3.12/unittest/runner.py"},{"path":"/usr/lib/python3.12/unittest/signals.py"},{"path":"/usr/lib/python3.12/unittest/suite.py"},{"path":"/usr/lib/python3.12/unittest/util.py"},{"path":"/usr/lib/python3.12/urllib"},{"path":"/usr/lib/python3.12/urllib/__init__.py"},{"path":"/usr/lib/python3.12/urllib/error.py"},{"path":"/usr/lib/python3.12/urllib/parse.py"},{"path":"/usr/lib/python3.12/urllib/request.py"},{"path":"/usr/lib/python3.12/urllib/response.py"},{"path":"/usr/lib/python3.12/urllib/robotparser.py"},{"path":"/usr/lib/python3.12/venv"},{"path":"/usr/lib/python3.12/venv/__init__.py"},{"path":"/usr/lib/python3.12/venv/__main__.py"},{"path":"/usr/lib/python3.12/venv/scripts"},{"path":"/usr/lib/python3.12/venv/scripts/common"},{"path":"/usr/lib/python3.12/venv/scripts/common/Activate.ps1"},{"path":"/usr/lib/python3.12/venv/scripts/common/activate"},{"path":"/usr/lib/python3.12/venv/scripts/posix"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.csh"},{"path":"/usr/lib/python3.12/venv/scripts/posix/activate.fish"},{"path":"/usr/lib/python3.12/wsgiref"},{"path":"/usr/lib/python3.12/wsgiref/__init__.py"},{"path":"/usr/lib/python3.12/wsgiref/handlers.py"},{"path":"/usr/lib/python3.12/wsgiref/headers.py"},{"path":"/usr/lib/python3.12/wsgiref/simple_server.py"},{"path":"/usr/lib/python3.12/wsgiref/types.py"},{"path":"/usr/lib/python3.12/wsgiref/util.py"},{"path":"/usr/lib/python3.12/wsgiref/validate.py"},{"path":"/usr/lib/python3.12/xml"},{"path":"/usr/lib/python3.12/xml/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom"},{"path":"/usr/lib/python3.12/xml/dom/NodeFilter.py"},{"path":"/usr/lib/python3.12/xml/dom/__init__.py"},{"path":"/usr/lib/python3.12/xml/dom/domreg.py"},{"path":"/usr/lib/python3.12/xml/dom/expatbuilder.py"},{"path":"/usr/lib/python3.12/xml/dom/minicompat.py"},{"path":"/usr/lib/python3.12/xml/dom/minidom.py"},{"path":"/usr/lib/python3.12/xml/dom/pulldom.py"},{"path":"/usr/lib/python3.12/xml/dom/xmlbuilder.py"},{"path":"/usr/lib/python3.12/xml/etree"},{"path":"/usr/lib/python3.12/xml/etree/ElementInclude.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementPath.py"},{"path":"/usr/lib/python3.12/xml/etree/ElementTree.py"},{"path":"/usr/lib/python3.12/xml/etree/__init__.py"},{"path":"/usr/lib/python3.12/xml/etree/cElementTree.py"},{"path":"/usr/lib/python3.12/xml/parsers"},{"path":"/usr/lib/python3.12/xml/parsers/__init__.py"},{"path":"/usr/lib/python3.12/xml/parsers/expat.py"},{"path":"/usr/lib/python3.12/xml/sax"},{"path":"/usr/lib/python3.12/xml/sax/__init__.py"},{"path":"/usr/lib/python3.12/xml/sax/_exceptions.py"},{"path":"/usr/lib/python3.12/xml/sax/expatreader.py"},{"path":"/usr/lib/python3.12/xml/sax/handler.py"},{"path":"/usr/lib/python3.12/xml/sax/saxutils.py"},{"path":"/usr/lib/python3.12/xml/sax/xmlreader.py"},{"path":"/usr/lib/python3.12/xmlrpc"},{"path":"/usr/lib/python3.12/xmlrpc/__init__.py"},{"path":"/usr/lib/python3.12/xmlrpc/client.py"},{"path":"/usr/lib/python3.12/xmlrpc/server.py"},{"path":"/usr/lib/python3.12/zipfile"},{"path":"/usr/lib/python3.12/zipfile/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/__main__.py"},{"path":"/usr/lib/python3.12/zipfile/_path"},{"path":"/usr/lib/python3.12/zipfile/_path/__init__.py"},{"path":"/usr/lib/python3.12/zipfile/_path/glob.py"},{"path":"/usr/lib/python3.12/zoneinfo"},{"path":"/usr/lib/python3.12/zoneinfo/__init__.py"},{"path":"/usr/lib/python3.12/zoneinfo/_common.py"},{"path":"/usr/lib/python3.12/zoneinfo/_tzpath.py"},{"path":"/usr/lib/python3.12/zoneinfo/_zoneinfo.py"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3479","versionConstraint":"< 3.13.13||>= 3.14.0, < 3.14.4||>= 3.15.0a1, < 3.15.0a8 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}},{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3479","versionConstraint":"< 3.13.13||>= 3.14.0, < 3.14.4||>= 3.15.0a1, < 3.15.0a8 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.12.15:*:*:*:*:*:*:*"],"package":{"name":"python3","version":"3.12.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-3479","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"risk":0.01225,"urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"severity":"Negligible","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."},"relatedVulnerabilities":[]},{"artifact":{"id":"d4c76feff162c414","cpes":["cpe:2.3:a:oauthlib_community_project:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community_project:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_communityproject:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_communityproject:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community_project:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_communityproject:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python-oauthlib:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python-oauthlib:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python_oauthlib:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python_oauthlib:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python-oauthlib:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python_oauthlib:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python:oauthlib:3.3.1:*:*:*:*:*:*:*"],"name":"oauthlib","purl":"pkg:pypi/oauthlib@3.3.1","type":"python","version":"3.3.1","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/top_level.txt","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hj66-6f7g-4r5v","versionConstraint":">=0.6.1,<=3.3.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"oauthlib","version":"3.3.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-hj66-6f7g-4r5v","fix":{"state":"fixed","versions":["4.0.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"4.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/oauthlib/oauthlib/security/advisories/GHSA-hj66-6f7g-4r5v","https://github.com/oauthlib/oauthlib/pull/951","https://github.com/oauthlib/oauthlib/commit/c888359f3c42bec235b2c5caab2069c9ed62457c"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hj66-6f7g-4r5v","description":"Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation"},"relatedVulnerabilities":[{"id":"CVE-2026-49264","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"d4c76feff162c414","cpes":["cpe:2.3:a:oauthlib_community_project:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community_project:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_communityproject:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_communityproject:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community_project:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_communityproject:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python-oauthlib:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python-oauthlib:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python_oauthlib:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python_oauthlib:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib_community:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python-oauthlib:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python_oauthlib:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oauthlib:oauthlib:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python:oauthlib:3.3.1:*:*:*:*:*:*:*"],"name":"oauthlib","purl":"pkg:pypi/oauthlib@3.3.1","type":"python","version":"3.3.1","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/METADATA","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/RECORD","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/top_level.txt","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/app/bazarr/bin/libs/oauthlib-3.3.1.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xpv3-w29h-x7cv","versionConstraint":">=3.0.0,<4.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"oauthlib","version":"3.3.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-xpv3-w29h-x7cv","fix":{"state":"fixed","versions":["4.0.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"4.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv","https://github.com/oauthlib/oauthlib/pull/963","https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xpv3-w29h-x7cv","description":"Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)"},"relatedVulnerabilities":[{"id":"CVE-2026-49265","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"cbd77e4fe96fe423","cpes":["cpe:2.3:a:rust-random:rand:0.9.1:*:*:*:*:rust:*:*"],"name":"rand","purl":"pkg:cargo/rand@0.9.1","type":"rust-crate","version":"0.9.1","language":"rust","licenses":[],"locations":[{"path":"/usr/lib/librav1e.so.0.8.1","layerID":"sha256:6377721f6cbf04d244612217622c1b7f547c71a47fc027a02f3d6b66dc93f82e","accessPath":"/usr/lib/librav1e.so.0.8.1","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.9.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cq8v-f236-94qc","versionConstraint":">=0.9.0,<0.9.3 (unknown)"},"matcher":"rust-matcher","searchedBy":{"package":{"name":"rand","version":"0.9.1"},"language":"rust","namespace":"github:language:rust"}}],"vulnerability":{"id":"GHSA-cq8v-f236-94qc","fix":{"state":"fixed","versions":["0.9.3"],"available":[{"date":"2026-04-14","kind":"first-observed","version":"0.9.3"}]},"cvss":[],"risk":0,"urls":["https://github.com/rust-random/rand/pull/1763","https://rustsec.org/advisories/RUSTSEC-2026-0097.html"],"severity":"Low","namespace":"github:language:rust","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cq8v-f236-94qc","description":"Rand is unsound with a custom logger using rand::rng()"},"relatedVulnerabilities":[]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:22:32.385Z","grype_db_version":"2026-10-09T06:32:32.000Z"}