{"grype_matches":[{"artifact":{"id":"cf3f4f305e651dab","cpes":["cpe:2.3:a:oracleamerica:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/ol/openssl@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.0.7-28.0.1.el9_4_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2024-12675","versionConstraint":"< 10:3.0.7-28.0.1.el9_4_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2024-12675","fix":{"state":"fixed","versions":["10:3.0.7-28.0.1.el9_4_fips"],"available":[{"date":"2024-09-19","kind":"advisory","version":"10:3.0.7-28.0.1.el9_4_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-6119","date":"2026-10-08","epss":0.66582,"percentile":0.99272}],"risk":33.291,"urls":["https://linux.oracle.com/cve/CVE-2024-6119.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2024-12675.html","description":"[3.0.7-28.0.1_fips]\n- Replace upstream references in fips man pages [Orabug: 35824276]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name and remove upstream references from\n  fips_module_indicators manpage [Orabug: 35824276]\n\n[3.0.7-28.0.1]\n- Drop OpenELA branding, apply Oracle branding patches\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[1:3.0.7-28]\n- Patch for CVE-2024-6119\n  Resolves: RHEL-55340"},"relatedVulnerabilities":[{"id":"CVE-2024-6119","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-6119","date":"2026-10-08","epss":0.66582,"percentile":0.99272}],"urls":["https://github.com/openssl/openssl/commit/05f360d9e849a1b277db628f1f13083a7f8dd04f","https://github.com/openssl/openssl/commit/06d1dc3fa96a2ba5a3e22735a033012aadc9f0d6","https://github.com/openssl/openssl/commit/621f3729831b05ee828a3203eddb621d014ff2b2","https://github.com/openssl/openssl/commit/7dfcee2cd2a63b2c64b9b4b0850be64cb695b0a0","https://openssl-library.org/news/secadv/20240903.txt","http://www.openwall.com/lists/oss-security/2024/09/03/4","https://lists.freebsd.org/archives/freebsd-security/2024-September/000303.html","https://security.netapp.com/advisory/ntap-20240912-0001/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-6119","description":"Issue summary: Applications performing certificate name checks (e.g., TLS\nclients checking server certificates) may attempt to read an invalid memory\naddress resulting in abnormal termination of the application process.\n\nImpact summary: Abnormal termination of an application can a cause a denial of\nservice.\n\nApplications performing certificate name checks (e.g., TLS clients checking\nserver certificates) may attempt to read an invalid memory address when\ncomparing the expected name with an `otherName` subject alternative name of an\nX.509 certificate. This may result in an exception that terminates the\napplication program.\n\nNote that basic certificate chain validation (signatures, dates, ...) is not\naffected, the denial of service can occur only when the application also\nspecifies an expected DNS name, Email address or IP address.\n\nTLS servers rarely solicit client certificates, and even when they do, they\ngenerally don't perform a name check against a reference identifier (expected\nidentity), but rather extract the presented identity after checking the\ncertificate chain.  So TLS servers are generally not affected and the severity\nof the issue is Moderate.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."}]},{"artifact":{"id":"dfd591701b2bf27b","cpes":["cpe:2.3:a:oracleamerica:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:oracleamerica:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/ol/openssl-libs@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.0.1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.0.7-28.0.1.el9_4_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2024-12675","versionConstraint":"< 10:3.0.7-28.0.1.el9_4_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl-libs","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2024-12675","fix":{"state":"fixed","versions":["10:3.0.7-28.0.1.el9_4_fips"],"available":[{"date":"2024-09-19","kind":"advisory","version":"10:3.0.7-28.0.1.el9_4_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-6119","date":"2026-10-08","epss":0.66582,"percentile":0.99272}],"risk":33.291,"urls":["https://linux.oracle.com/cve/CVE-2024-6119.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2024-12675.html","description":"[3.0.7-28.0.1_fips]\n- Replace upstream references in fips man pages [Orabug: 35824276]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name and remove upstream references from\n  fips_module_indicators manpage [Orabug: 35824276]\n\n[3.0.7-28.0.1]\n- Drop OpenELA branding, apply Oracle branding patches\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[1:3.0.7-28]\n- Patch for CVE-2024-6119\n  Resolves: RHEL-55340"},"relatedVulnerabilities":[{"id":"CVE-2024-6119","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-6119","date":"2026-10-08","epss":0.66582,"percentile":0.99272}],"urls":["https://github.com/openssl/openssl/commit/05f360d9e849a1b277db628f1f13083a7f8dd04f","https://github.com/openssl/openssl/commit/06d1dc3fa96a2ba5a3e22735a033012aadc9f0d6","https://github.com/openssl/openssl/commit/621f3729831b05ee828a3203eddb621d014ff2b2","https://github.com/openssl/openssl/commit/7dfcee2cd2a63b2c64b9b4b0850be64cb695b0a0","https://openssl-library.org/news/secadv/20240903.txt","http://www.openwall.com/lists/oss-security/2024/09/03/4","https://lists.freebsd.org/archives/freebsd-security/2024-September/000303.html","https://security.netapp.com/advisory/ntap-20240912-0001/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-6119","description":"Issue summary: Applications performing certificate name checks (e.g., TLS\nclients checking server certificates) may attempt to read an invalid memory\naddress resulting in abnormal termination of the application process.\n\nImpact summary: Abnormal termination of an application can a cause a denial of\nservice.\n\nApplications performing certificate name checks (e.g., TLS clients checking\nserver certificates) may attempt to read an invalid memory address when\ncomparing the expected name with an `otherName` subject alternative name of an\nX.509 certificate. This may result in an exception that terminates the\napplication program.\n\nNote that basic certificate chain validation (signatures, dates, ...) is not\naffected, the denial of service can occur only when the application also\nspecifies an expected DNS name, Email address or IP address.\n\nTLS servers rarely solicit client certificates, and even when they do, they\ngenerally don't perform a name check against a reference identifier (expected\nidentity), but rather extract the presented identity after checking the\ncertificate chain.  So TLS servers are generally not affected and the severity\nof the issue is Moderate.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."}]},{"artifact":{"id":"cf3f4f305e651dab","cpes":["cpe:2.3:a:oracleamerica:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/ol/openssl@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.5.1-7.0.1.el9_7_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-50075","versionConstraint":"< 10:3.5.1-7.0.1.el9_7_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-50075","fix":{"state":"fixed","versions":["10:3.5.1-7.0.1.el9_7_fips"],"available":[{"date":"2026-01-29","kind":"advisory","version":"10:3.5.1-7.0.1.el9_7_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-11187","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-11187","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-15467","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-15467","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"cve":"CVE-2025-15468","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-15469","cwe":"CWE-347","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-66199","cwe":"CWE-789","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-68160","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-69418","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-69419","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-69420","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-69421","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-22795","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-22796","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-11187","date":"2026-10-08","epss":0.05139,"percentile":0.92192},{"cve":"CVE-2025-15467","date":"2026-10-08","epss":0.52446,"percentile":0.98938},{"cve":"CVE-2025-15468","date":"2026-10-08","epss":0.00831,"percentile":0.56284},{"cve":"CVE-2025-15469","date":"2026-10-08","epss":0.00202,"percentile":0.09227},{"cve":"CVE-2025-66199","date":"2026-10-08","epss":0.00453,"percentile":0.37334},{"cve":"CVE-2025-68160","date":"2026-10-08","epss":0.00178,"percentile":0.0678},{"cve":"CVE-2025-69418","date":"2026-10-08","epss":0.00129,"percentile":0.02225},{"cve":"CVE-2025-69419","date":"2026-10-08","epss":0.00616,"percentile":0.47921},{"cve":"CVE-2025-69420","date":"2026-10-08","epss":0.00899,"percentile":0.58405},{"cve":"CVE-2025-69421","date":"2026-10-08","epss":0.00958,"percentile":0.60302},{"cve":"CVE-2026-22795","date":"2026-10-08","epss":0.00169,"percentile":0.0568},{"cve":"CVE-2026-22796","date":"2026-10-08","epss":0.00576,"percentile":0.45751}],"risk":3.85425,"urls":["https://linux.oracle.com/cve/CVE-2025-11187.html","https://linux.oracle.com/cve/CVE-2025-15467.html","https://linux.oracle.com/cve/CVE-2025-15468.html","https://linux.oracle.com/cve/CVE-2025-15469.html","https://linux.oracle.com/cve/CVE-2025-66199.html","https://linux.oracle.com/cve/CVE-2025-68160.html","https://linux.oracle.com/cve/CVE-2025-69418.html","https://linux.oracle.com/cve/CVE-2025-69419.html","https://linux.oracle.com/cve/CVE-2025-69420.html","https://linux.oracle.com/cve/CVE-2025-69421.html","https://linux.oracle.com/cve/CVE-2026-22795.html","https://linux.oracle.com/cve/CVE-2026-22796.html"],"severity":"High","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-50075.html","description":"[3.5.1-7.0.1_fips]\n- Update additional upstream references\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name [Orabug: 35824276]\n\n[3.5.1-7.0.1]\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[3.5.1.openela.0.1]\n- Add OpenELA specific changes\n\n[1:3.5.1-7]\n- Fix CVE-2025-11187 CVE-2025-15467 CVE-2025-15468 CVE-2025-15469\n  CVE-2025-66199 CVE-2025-68160 CVE-2025-69418 CVE-2025-69419 CVE-2025-69420\n  CVE-2025-69421 CVE-2026-22795 CVE-2026-22796\n  Resolves: RHEL-142068\n  Resolves: RHEL-142002\n  Resolves: RHEL-142055\n  Resolves: RHEL-142051\n  Resolves: RHEL-142047\n  Resolves: RHEL-142043\n  Resolves: RHEL-142039\n  Resolves: RHEL-142035\n  Resolves: RHEL-142031\n  Resolves: RHEL-142011\n  Resolves: RHEL-142027\n  Resolves: RHEL-142023\n\n[1:3.5.1-6]\n- Fix AES/GCM ppc64le encrypt/decrypt\n  Resolves: RHEL-139131"},"relatedVulnerabilities":[{"id":"CVE-2025-11187","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11187","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-11187","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-11187","date":"2026-10-08","epss":0.05139,"percentile":0.92192}],"urls":["https://github.com/openssl/openssl/commit/205e3a55e16e4bd08c12fdbd3416ab829c0f6206","https://github.com/openssl/openssl/commit/8caf359d6e46fb413e8f5f0df765d2e8a51df4e8","https://github.com/openssl/openssl/commit/e1079bc17ed93ff16f6b86f33a2fe3336e78817e","https://openssl-library.org/news/secadv/20260127.txt","https://github.com/metadust/CVE-2025-11187"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11187","description":"Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation\nwhich can trigger a stack-based buffer overflow, invalid pointer or NULL\npointer dereference during MAC verification.\n\nImpact summary: The stack buffer overflow or NULL pointer dereference may\ncause a crash leading to Denial of Service for an application that parses\nuntrusted PKCS#12 files. The buffer overflow may also potentially enable\ncode execution depending on platform mitigations.\n\nWhen verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2\nsalt and keylength parameters from the file are used without validation.\nIf the value of keylength exceeds the size of the fixed stack buffer used\nfor the derived key (64 bytes), the key derivation will overflow the buffer.\nThe overflow length is attacker-controlled. Also, if the salt parameter is\nnot an OCTET STRING type this can lead to invalid or NULL pointer\ndereference.\n\nExploiting this issue requires a user or application to process\na maliciously crafted PKCS#12 file. It is uncommon to accept untrusted\nPKCS#12 files in applications as they are usually used to store private\nkeys which are trusted by definition. For this reason the issue was assessed\nas Moderate severity.\n\nThe FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as\nPKCS#12 processing is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.\n\nOpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do\nnot support PBMAC1 in PKCS#12."},{"id":"CVE-2025-15467","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15467","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-15467","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-15467","date":"2026-10-08","epss":0.52446,"percentile":0.98938}],"urls":["https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703","https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9","https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3","https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e","https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc","https://openssl-library.org/news/secadv/20260127.txt","http://www.openwall.com/lists/oss-security/2026/01/27/10","http://www.openwall.com/lists/oss-security/2026/02/25/6","https://access.redhat.com/errata/RHSA-2026:1472","https://access.redhat.com/errata/RHSA-2026:1473","https://access.redhat.com/errata/RHSA-2026:1496","https://access.redhat.com/errata/RHSA-2026:1503","https://access.redhat.com/errata/RHSA-2026:1519","https://access.redhat.com/errata/RHSA-2026:1594","https://access.redhat.com/errata/RHSA-2026:1733","https://access.redhat.com/errata/RHSA-2026:1736","https://access.redhat.com/errata/RHSA-2026:2072","https://access.redhat.com/errata/RHSA-2026:2077","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2633","https://access.redhat.com/errata/RHSA-2026:2659","https://access.redhat.com/errata/RHSA-2026:2671","https://access.redhat.com/errata/RHSA-2026:2844","https://access.redhat.com/errata/RHSA-2026:2974","https://access.redhat.com/errata/RHSA-2026:2995","https://access.redhat.com/errata/RHSA-2026:3228","https://access.redhat.com/errata/RHSA-2026:3415","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:4419","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:6481","https://access.redhat.com/errata/RHSA-2026:7261","https://access.redhat.com/security/cve/CVE-2025-15467","https://bugzilla.redhat.com/show_bug.cgi?id=2430376","https://cert-portal.siemens.com/productcert/html/ssa-434797.html","https://cert-portal.siemens.com/productcert/html/ssa-734552.html","https://github.com/guiimoraes/CVE-2025-15467","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15467","description":"Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with\nmaliciously crafted AEAD parameters can trigger a stack buffer overflow.\n\nImpact summary: A stack buffer overflow may lead to a crash, causing Denial\nof Service, or potentially remote code execution.\n\nWhen parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as\nAES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is\ncopied into a fixed-size stack buffer without verifying that its length fits\nthe destination. An attacker can supply a crafted CMS message with an\noversized IV, causing a stack-based out-of-bounds write before any\nauthentication or tag verification occurs.\n\nApplications and services that parse untrusted CMS or PKCS#7 content using\nAEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.\nBecause the overflow occurs prior to authentication, no valid key material\nis required to trigger it. While exploitability to remote code execution\ndepends on platform and toolchain mitigations, the stack-based write\nprimitive represents a severe risk.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.\n\nOpenSSL 1.1.1 and 1.0.2 are not affected by this issue."},{"id":"CVE-2025-15468","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15468","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-15468","date":"2026-10-08","epss":0.00831,"percentile":0.56284}],"urls":["https://github.com/openssl/openssl/commit/1f08e54bad32843044fe8a675948d65e3b4ece65","https://github.com/openssl/openssl/commit/7c88376731c589ee5b36116c5a6e32d5ae5f7ae2","https://github.com/openssl/openssl/commit/b2539639400288a4580fe2d76247541b976bade4","https://github.com/openssl/openssl/commit/d75b309879631d45b972396ce4e5102559c64ac7","https://openssl-library.org/news/secadv/20260127.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15468","description":"Issue summary: If an application using the SSL_CIPHER_find() function in\na QUIC protocol client or server receives an unknown cipher suite from\nthe peer, a NULL dereference occurs.\n\nImpact summary: A NULL pointer dereference leads to abnormal termination of\nthe running process causing Denial of Service.\n\nSome applications call SSL_CIPHER_find() from the client_hello_cb callback\non the cipher ID received from the peer. If this is done with an SSL object\nimplementing the QUIC protocol, NULL pointer dereference will happen if\nthe examined cipher ID is unknown or unsupported.\n\nAs it is not very common to call this function in applications using the QUIC \nprotocol and the worst outcome is Denial of Service, the issue was assessed\nas Low severity.\n\nThe vulnerable code was introduced in the 3.2 version with the addition\nof the QUIC protocol support.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the QUIC implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue."},{"id":"CVE-2025-15469","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15469","cwe":"CWE-347","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-15469","date":"2026-10-08","epss":0.00202,"percentile":0.09227}],"urls":["https://github.com/openssl/openssl/commit/310f305eb92ea8040d6b3cb75a5feeba8e6acf2f","https://github.com/openssl/openssl/commit/a7936fa4bd23c906e1955a16a0a0ab39a4953a61","https://openssl-library.org/news/secadv/20260127.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15469","description":"Issue summary: The 'openssl dgst' command-line tool silently truncates input\ndata to 16MB when using one-shot signing algorithms and reports success instead\nof an error.\n\nImpact summary: A user signing or verifying files larger than 16MB with\none-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire\nfile is authenticated while trailing data beyond 16MB remains unauthenticated.\n\nWhen the 'openssl dgst' command is used with algorithms that only support\none-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input\nis buffered with a 16MB limit. If the input exceeds this limit, the tool\nsilently truncates to the first 16MB and continues without signaling an error,\ncontrary to what the documentation states. This creates an integrity gap where\ntrailing bytes can be modified without detection if both signing and\nverification are performed using the same affected codepath.\n\nThe issue affects only the command-line tool behavior. Verifiers that process\nthe full message using library APIs will reject the signature, so the risk\nprimarily affects workflows that both sign and verify with the affected\n'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and\nlibrary users are unaffected.\n\nThe FIPS modules in 3.5 and 3.6 are not affected by this issue, as the\ncommand-line tools are outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.5 and 3.6 are vulnerable to this issue.\n\nOpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue."},{"id":"CVE-2025-66199","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66199","cwe":"CWE-789","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-66199","date":"2026-10-08","epss":0.00453,"percentile":0.37334}],"urls":["https://github.com/openssl/openssl/commit/3ed1f75249932b155eef993a8e66a99cb98bfef4","https://github.com/openssl/openssl/commit/6184a4fb08ee6d7bca570d931a4e8bef40b64451","https://github.com/openssl/openssl/commit/895150b5e021d16b52fb32b97e1dd12f20448be5","https://github.com/openssl/openssl/commit/966a2478046c311ed7dae50c457d0db4cafbf7e4","https://openssl-library.org/news/secadv/20260127.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66199","description":"Issue summary: A TLS 1.3 connection using certificate compression can be\nforced to allocate a large buffer before decompression without checking\nagainst the configured certificate size limit.\n\nImpact summary: An attacker can cause per-connection memory allocations of\nup to approximately 22 MiB and extra CPU work, potentially leading to\nservice degradation or resource exhaustion (Denial of Service).\n\nIn affected configurations, the peer-supplied uncompressed certificate\nlength from a CompressedCertificate message is used to grow a heap buffer\nprior to decompression. This length is not bounded by the max_cert_list\nsetting, which otherwise constrains certificate message sizes. An attacker\ncan exploit this to cause large per-connection allocations followed by\nhandshake failure. No memory corruption or information disclosure occurs.\n\nThis issue only affects builds where TLS 1.3 certificate compression is\ncompiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression\nalgorithm (brotli, zlib, or zstd) is available, and where the compression\nextension is negotiated. Both clients receiving a server CompressedCertificate\nand servers in mutual TLS scenarios receiving a client CompressedCertificate\nare affected. Servers that do not request client certificates are not\nvulnerable to client-initiated attacks.\n\nUsers can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\nto disable receiving compressed certificates.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the TLS implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue."},{"id":"CVE-2025-68160","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68160","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-68160","date":"2026-10-08","epss":0.00178,"percentile":0.0678}],"urls":["https://github.com/openssl/openssl/commit/384011202af92605d926fafe4a0bcd6b65d162ad","https://github.com/openssl/openssl/commit/475c466ef2fbd8fc1df6fae1c3eed9c813fc8ff6","https://github.com/openssl/openssl/commit/4c96fbba618e1940f038012506ee9e21d32ee12c","https://github.com/openssl/openssl/commit/6845c3b6460a98b1ec4e463baa2ea1a63a32d7c0","https://github.com/openssl/openssl/commit/68a7cd2e2816c3a02f4d45a2ce43fc04fac97096","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68160","description":"Issue summary: Writing large, newline-free data into a BIO chain using the\nline-buffering filter where the next BIO performs short writes can trigger\na heap-based out-of-bounds write.\n\nImpact summary: This out-of-bounds write can cause memory corruption which\ntypically results in a crash, leading to Denial of Service for an application.\n\nThe line-buffering BIO filter (BIO_f_linebuffer) is not used by default in\nTLS/SSL data paths. In OpenSSL command-line applications, it is typically\nonly pushed onto stdout/stderr on VMS systems. Third-party applications that\nexplicitly use this filter with a BIO chain that can short-write and that\nwrite large, newline-free data influenced by an attacker would be affected.\nHowever, the circumstances where this could happen are unlikely to be under\nattacker control, and BIO_f_linebuffer is unlikely to be handling non-curated\ndata controlled by an attacker. For that reason the issue was assessed as\nLow severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the BIO implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."},{"id":"CVE-2025-69418","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4,"impactScore":2.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69418","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69418","date":"2026-10-08","epss":0.00129,"percentile":0.02225}],"urls":["https://github.com/openssl/openssl/commit/372fc5c77529695b05b4f5b5187691a57ef5dffc","https://github.com/openssl/openssl/commit/4016975d4469cd6b94927c607f7c511385f928d8","https://github.com/openssl/openssl/commit/52d23c86a54adab5ee9f80e48b242b52c4cc2347","https://github.com/openssl/openssl/commit/a7589230356d908c0eca4b969ec4f62106f4f5ae","https://github.com/openssl/openssl/commit/ed40856d7d4ba6cb42779b6770666a65f19cb977","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69418","description":"Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue."},{"id":"CVE-2025-69419","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69419","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69419","date":"2026-10-08","epss":0.00616,"percentile":0.47921}],"urls":["https://github.com/openssl/openssl/commit/41be0f216404f14457bbf3b9cc488dba60b49296","https://github.com/openssl/openssl/commit/7e9cac9832e4705b91987c2474ed06a37a93cecb","https://github.com/openssl/openssl/commit/a26a90d38edec3748566129d824e664b54bee2e2","https://github.com/openssl/openssl/commit/cda12de3bc0e333ea8d2c6fd15001dbdaf280015","https://github.com/openssl/openssl/commit/ff628933755075446bca8307e8417c14d164b535","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69419","description":"Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously\ncrafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing\nnon-ASCII BMP code point can trigger a one byte write before the allocated\nbuffer.\n\nImpact summary: The out-of-bounds write can cause a memory corruption\nwhich can have various consequences including a Denial of Service.\n\nThe OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12\nBMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes,\nthe helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16\nsource byte count as the destination buffer capacity to UTF8_putc(). For BMP\ncode points above U+07FF, UTF-8 requires three bytes, but the forwarded\ncapacity can be just two bytes. UTF8_putc() then returns -1, and this negative\nvalue is added to the output length without validation, causing the\nlength to become negative. The subsequent trailing NUL byte is then written\nat a negative offset, causing write outside of heap allocated buffer.\n\nThe vulnerability is reachable via the public PKCS12_get_friendlyname() API\nwhen parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a\ndifferent code path that avoids this issue, PKCS12_get_friendlyname() directly\ninvokes the vulnerable function. Exploitation requires an attacker to provide\na malicious PKCS#12 file to be parsed by the application and the attacker\ncan just trigger a one zero byte write before the allocated buffer.\nFor that reason the issue was assessed as Low severity according to our\nSecurity Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."},{"id":"CVE-2025-69420","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69420","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69420","date":"2026-10-08","epss":0.00899,"percentile":0.58405}],"urls":["https://github.com/openssl/openssl/commit/27c7012c91cc986a598d7540f3079dfde2416eb9","https://github.com/openssl/openssl/commit/4e254b48ad93cc092be3dd62d97015f33f73133a","https://github.com/openssl/openssl/commit/564fd9c73787f25693bf9e75faf7bf6bb1305d4e","https://github.com/openssl/openssl/commit/5eb0770ffcf11b785cf374ff3c19196245e54f1b","https://github.com/openssl/openssl/commit/a99349ebfc519999edc50620abe24d599b9eb085","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69420","description":"Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."},{"id":"CVE-2025-69421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69421","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69421","date":"2026-10-08","epss":0.00958,"percentile":0.60302}],"urls":["https://github.com/openssl/openssl/commit/3524a29271f8191b8fd8a5257eb05173982a097b","https://github.com/openssl/openssl/commit/36ecb4960872a4ce04bf6f1e1f4e78d75ec0c0c7","https://github.com/openssl/openssl/commit/4bbc8d41a72c842ce4077a8a3eccd1109aaf74bd","https://github.com/openssl/openssl/commit/643986985cd1c21221f941129d76fe0c2785aeb3","https://github.com/openssl/openssl/commit/a2dbc539f0f9cc63832709fa5aa33ad9495eb19c","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69421","description":"Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\n\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\n\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."},{"id":"CVE-2026-22795","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22795","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-22795","date":"2026-10-08","epss":0.00169,"percentile":0.0568}],"urls":["https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4","https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49","https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12","https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e","https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22795","description":"Issue summary: An invalid or NULL pointer dereference can happen in\nan application processing a malformed PKCS#12 file.\n\nImpact summary: An application processing a malformed PKCS#12 file can be\ncaused to dereference an invalid or NULL pointer on memory read, resulting\nin a Denial of Service.\n\nA type confusion vulnerability exists in PKCS#12 parsing code where\nan ASN1_TYPE union member is accessed without first validating the type,\ncausing an invalid pointer read.\n\nThe location is constrained to a 1-byte address space, meaning any\nattempted pointer manipulation can only target addresses between 0x00 and 0xFF.\nThis range corresponds to the zero page, which is unmapped on most modern\noperating systems and will reliably result in a crash, leading only to a\nDenial of Service. Exploiting this issue also requires a user or application\nto process a maliciously crafted PKCS#12 file. It is uncommon to accept\nuntrusted PKCS#12 files in applications as they are usually used to store\nprivate keys which are trusted by definition. For these reasons, the issue\nwas assessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."},{"id":"CVE-2026-22796","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22796","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-22796","date":"2026-10-08","epss":0.00576,"percentile":0.45751}],"urls":["https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4","https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49","https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12","https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e","https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22796","description":"Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."}]},{"artifact":{"id":"dfd591701b2bf27b","cpes":["cpe:2.3:a:oracleamerica:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:oracleamerica:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/ol/openssl-libs@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.0.1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.5.1-7.0.1.el9_7_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-50075","versionConstraint":"< 10:3.5.1-7.0.1.el9_7_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl-libs","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-50075","fix":{"state":"fixed","versions":["10:3.5.1-7.0.1.el9_7_fips"],"available":[{"date":"2026-01-29","kind":"advisory","version":"10:3.5.1-7.0.1.el9_7_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-11187","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-11187","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-15467","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-15467","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"cve":"CVE-2025-15468","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-15469","cwe":"CWE-347","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-66199","cwe":"CWE-789","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-68160","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-69418","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-69419","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-69420","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-69421","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-22795","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-22796","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-11187","date":"2026-10-08","epss":0.05139,"percentile":0.92192},{"cve":"CVE-2025-15467","date":"2026-10-08","epss":0.52446,"percentile":0.98938},{"cve":"CVE-2025-15468","date":"2026-10-08","epss":0.00831,"percentile":0.56284},{"cve":"CVE-2025-15469","date":"2026-10-08","epss":0.00202,"percentile":0.09227},{"cve":"CVE-2025-66199","date":"2026-10-08","epss":0.00453,"percentile":0.37334},{"cve":"CVE-2025-68160","date":"2026-10-08","epss":0.00178,"percentile":0.0678},{"cve":"CVE-2025-69418","date":"2026-10-08","epss":0.00129,"percentile":0.02225},{"cve":"CVE-2025-69419","date":"2026-10-08","epss":0.00616,"percentile":0.47921},{"cve":"CVE-2025-69420","date":"2026-10-08","epss":0.00899,"percentile":0.58405},{"cve":"CVE-2025-69421","date":"2026-10-08","epss":0.00958,"percentile":0.60302},{"cve":"CVE-2026-22795","date":"2026-10-08","epss":0.00169,"percentile":0.0568},{"cve":"CVE-2026-22796","date":"2026-10-08","epss":0.00576,"percentile":0.45751}],"risk":3.85425,"urls":["https://linux.oracle.com/cve/CVE-2025-11187.html","https://linux.oracle.com/cve/CVE-2025-15467.html","https://linux.oracle.com/cve/CVE-2025-15468.html","https://linux.oracle.com/cve/CVE-2025-15469.html","https://linux.oracle.com/cve/CVE-2025-66199.html","https://linux.oracle.com/cve/CVE-2025-68160.html","https://linux.oracle.com/cve/CVE-2025-69418.html","https://linux.oracle.com/cve/CVE-2025-69419.html","https://linux.oracle.com/cve/CVE-2025-69420.html","https://linux.oracle.com/cve/CVE-2025-69421.html","https://linux.oracle.com/cve/CVE-2026-22795.html","https://linux.oracle.com/cve/CVE-2026-22796.html"],"severity":"High","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-50075.html","description":"[3.5.1-7.0.1_fips]\n- Update additional upstream references\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name [Orabug: 35824276]\n\n[3.5.1-7.0.1]\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[3.5.1.openela.0.1]\n- Add OpenELA specific changes\n\n[1:3.5.1-7]\n- Fix CVE-2025-11187 CVE-2025-15467 CVE-2025-15468 CVE-2025-15469\n  CVE-2025-66199 CVE-2025-68160 CVE-2025-69418 CVE-2025-69419 CVE-2025-69420\n  CVE-2025-69421 CVE-2026-22795 CVE-2026-22796\n  Resolves: RHEL-142068\n  Resolves: RHEL-142002\n  Resolves: RHEL-142055\n  Resolves: RHEL-142051\n  Resolves: RHEL-142047\n  Resolves: RHEL-142043\n  Resolves: RHEL-142039\n  Resolves: RHEL-142035\n  Resolves: RHEL-142031\n  Resolves: RHEL-142011\n  Resolves: RHEL-142027\n  Resolves: RHEL-142023\n\n[1:3.5.1-6]\n- Fix AES/GCM ppc64le encrypt/decrypt\n  Resolves: RHEL-139131"},"relatedVulnerabilities":[{"id":"CVE-2025-11187","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11187","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-11187","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-11187","date":"2026-10-08","epss":0.05139,"percentile":0.92192}],"urls":["https://github.com/openssl/openssl/commit/205e3a55e16e4bd08c12fdbd3416ab829c0f6206","https://github.com/openssl/openssl/commit/8caf359d6e46fb413e8f5f0df765d2e8a51df4e8","https://github.com/openssl/openssl/commit/e1079bc17ed93ff16f6b86f33a2fe3336e78817e","https://openssl-library.org/news/secadv/20260127.txt","https://github.com/metadust/CVE-2025-11187"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11187","description":"Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation\nwhich can trigger a stack-based buffer overflow, invalid pointer or NULL\npointer dereference during MAC verification.\n\nImpact summary: The stack buffer overflow or NULL pointer dereference may\ncause a crash leading to Denial of Service for an application that parses\nuntrusted PKCS#12 files. The buffer overflow may also potentially enable\ncode execution depending on platform mitigations.\n\nWhen verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2\nsalt and keylength parameters from the file are used without validation.\nIf the value of keylength exceeds the size of the fixed stack buffer used\nfor the derived key (64 bytes), the key derivation will overflow the buffer.\nThe overflow length is attacker-controlled. Also, if the salt parameter is\nnot an OCTET STRING type this can lead to invalid or NULL pointer\ndereference.\n\nExploiting this issue requires a user or application to process\na maliciously crafted PKCS#12 file. It is uncommon to accept untrusted\nPKCS#12 files in applications as they are usually used to store private\nkeys which are trusted by definition. For this reason the issue was assessed\nas Moderate severity.\n\nThe FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as\nPKCS#12 processing is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.\n\nOpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do\nnot support PBMAC1 in PKCS#12."},{"id":"CVE-2025-15467","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15467","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-15467","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-15467","date":"2026-10-08","epss":0.52446,"percentile":0.98938}],"urls":["https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703","https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9","https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3","https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e","https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc","https://openssl-library.org/news/secadv/20260127.txt","http://www.openwall.com/lists/oss-security/2026/01/27/10","http://www.openwall.com/lists/oss-security/2026/02/25/6","https://access.redhat.com/errata/RHSA-2026:1472","https://access.redhat.com/errata/RHSA-2026:1473","https://access.redhat.com/errata/RHSA-2026:1496","https://access.redhat.com/errata/RHSA-2026:1503","https://access.redhat.com/errata/RHSA-2026:1519","https://access.redhat.com/errata/RHSA-2026:1594","https://access.redhat.com/errata/RHSA-2026:1733","https://access.redhat.com/errata/RHSA-2026:1736","https://access.redhat.com/errata/RHSA-2026:2072","https://access.redhat.com/errata/RHSA-2026:2077","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2633","https://access.redhat.com/errata/RHSA-2026:2659","https://access.redhat.com/errata/RHSA-2026:2671","https://access.redhat.com/errata/RHSA-2026:2844","https://access.redhat.com/errata/RHSA-2026:2974","https://access.redhat.com/errata/RHSA-2026:2995","https://access.redhat.com/errata/RHSA-2026:3228","https://access.redhat.com/errata/RHSA-2026:3415","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:4419","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:6481","https://access.redhat.com/errata/RHSA-2026:7261","https://access.redhat.com/security/cve/CVE-2025-15467","https://bugzilla.redhat.com/show_bug.cgi?id=2430376","https://cert-portal.siemens.com/productcert/html/ssa-434797.html","https://cert-portal.siemens.com/productcert/html/ssa-734552.html","https://github.com/guiimoraes/CVE-2025-15467","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15467","description":"Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with\nmaliciously crafted AEAD parameters can trigger a stack buffer overflow.\n\nImpact summary: A stack buffer overflow may lead to a crash, causing Denial\nof Service, or potentially remote code execution.\n\nWhen parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as\nAES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is\ncopied into a fixed-size stack buffer without verifying that its length fits\nthe destination. An attacker can supply a crafted CMS message with an\noversized IV, causing a stack-based out-of-bounds write before any\nauthentication or tag verification occurs.\n\nApplications and services that parse untrusted CMS or PKCS#7 content using\nAEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.\nBecause the overflow occurs prior to authentication, no valid key material\nis required to trigger it. While exploitability to remote code execution\ndepends on platform and toolchain mitigations, the stack-based write\nprimitive represents a severe risk.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.\n\nOpenSSL 1.1.1 and 1.0.2 are not affected by this issue."},{"id":"CVE-2025-15468","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15468","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-15468","date":"2026-10-08","epss":0.00831,"percentile":0.56284}],"urls":["https://github.com/openssl/openssl/commit/1f08e54bad32843044fe8a675948d65e3b4ece65","https://github.com/openssl/openssl/commit/7c88376731c589ee5b36116c5a6e32d5ae5f7ae2","https://github.com/openssl/openssl/commit/b2539639400288a4580fe2d76247541b976bade4","https://github.com/openssl/openssl/commit/d75b309879631d45b972396ce4e5102559c64ac7","https://openssl-library.org/news/secadv/20260127.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15468","description":"Issue summary: If an application using the SSL_CIPHER_find() function in\na QUIC protocol client or server receives an unknown cipher suite from\nthe peer, a NULL dereference occurs.\n\nImpact summary: A NULL pointer dereference leads to abnormal termination of\nthe running process causing Denial of Service.\n\nSome applications call SSL_CIPHER_find() from the client_hello_cb callback\non the cipher ID received from the peer. If this is done with an SSL object\nimplementing the QUIC protocol, NULL pointer dereference will happen if\nthe examined cipher ID is unknown or unsupported.\n\nAs it is not very common to call this function in applications using the QUIC \nprotocol and the worst outcome is Denial of Service, the issue was assessed\nas Low severity.\n\nThe vulnerable code was introduced in the 3.2 version with the addition\nof the QUIC protocol support.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the QUIC implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue."},{"id":"CVE-2025-15469","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15469","cwe":"CWE-347","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-15469","date":"2026-10-08","epss":0.00202,"percentile":0.09227}],"urls":["https://github.com/openssl/openssl/commit/310f305eb92ea8040d6b3cb75a5feeba8e6acf2f","https://github.com/openssl/openssl/commit/a7936fa4bd23c906e1955a16a0a0ab39a4953a61","https://openssl-library.org/news/secadv/20260127.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15469","description":"Issue summary: The 'openssl dgst' command-line tool silently truncates input\ndata to 16MB when using one-shot signing algorithms and reports success instead\nof an error.\n\nImpact summary: A user signing or verifying files larger than 16MB with\none-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire\nfile is authenticated while trailing data beyond 16MB remains unauthenticated.\n\nWhen the 'openssl dgst' command is used with algorithms that only support\none-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input\nis buffered with a 16MB limit. If the input exceeds this limit, the tool\nsilently truncates to the first 16MB and continues without signaling an error,\ncontrary to what the documentation states. This creates an integrity gap where\ntrailing bytes can be modified without detection if both signing and\nverification are performed using the same affected codepath.\n\nThe issue affects only the command-line tool behavior. Verifiers that process\nthe full message using library APIs will reject the signature, so the risk\nprimarily affects workflows that both sign and verify with the affected\n'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and\nlibrary users are unaffected.\n\nThe FIPS modules in 3.5 and 3.6 are not affected by this issue, as the\ncommand-line tools are outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.5 and 3.6 are vulnerable to this issue.\n\nOpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue."},{"id":"CVE-2025-66199","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66199","cwe":"CWE-789","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-66199","date":"2026-10-08","epss":0.00453,"percentile":0.37334}],"urls":["https://github.com/openssl/openssl/commit/3ed1f75249932b155eef993a8e66a99cb98bfef4","https://github.com/openssl/openssl/commit/6184a4fb08ee6d7bca570d931a4e8bef40b64451","https://github.com/openssl/openssl/commit/895150b5e021d16b52fb32b97e1dd12f20448be5","https://github.com/openssl/openssl/commit/966a2478046c311ed7dae50c457d0db4cafbf7e4","https://openssl-library.org/news/secadv/20260127.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66199","description":"Issue summary: A TLS 1.3 connection using certificate compression can be\nforced to allocate a large buffer before decompression without checking\nagainst the configured certificate size limit.\n\nImpact summary: An attacker can cause per-connection memory allocations of\nup to approximately 22 MiB and extra CPU work, potentially leading to\nservice degradation or resource exhaustion (Denial of Service).\n\nIn affected configurations, the peer-supplied uncompressed certificate\nlength from a CompressedCertificate message is used to grow a heap buffer\nprior to decompression. This length is not bounded by the max_cert_list\nsetting, which otherwise constrains certificate message sizes. An attacker\ncan exploit this to cause large per-connection allocations followed by\nhandshake failure. No memory corruption or information disclosure occurs.\n\nThis issue only affects builds where TLS 1.3 certificate compression is\ncompiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression\nalgorithm (brotli, zlib, or zstd) is available, and where the compression\nextension is negotiated. Both clients receiving a server CompressedCertificate\nand servers in mutual TLS scenarios receiving a client CompressedCertificate\nare affected. Servers that do not request client certificates are not\nvulnerable to client-initiated attacks.\n\nUsers can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\nto disable receiving compressed certificates.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the TLS implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue."},{"id":"CVE-2025-68160","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68160","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-68160","date":"2026-10-08","epss":0.00178,"percentile":0.0678}],"urls":["https://github.com/openssl/openssl/commit/384011202af92605d926fafe4a0bcd6b65d162ad","https://github.com/openssl/openssl/commit/475c466ef2fbd8fc1df6fae1c3eed9c813fc8ff6","https://github.com/openssl/openssl/commit/4c96fbba618e1940f038012506ee9e21d32ee12c","https://github.com/openssl/openssl/commit/6845c3b6460a98b1ec4e463baa2ea1a63a32d7c0","https://github.com/openssl/openssl/commit/68a7cd2e2816c3a02f4d45a2ce43fc04fac97096","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68160","description":"Issue summary: Writing large, newline-free data into a BIO chain using the\nline-buffering filter where the next BIO performs short writes can trigger\na heap-based out-of-bounds write.\n\nImpact summary: This out-of-bounds write can cause memory corruption which\ntypically results in a crash, leading to Denial of Service for an application.\n\nThe line-buffering BIO filter (BIO_f_linebuffer) is not used by default in\nTLS/SSL data paths. In OpenSSL command-line applications, it is typically\nonly pushed onto stdout/stderr on VMS systems. Third-party applications that\nexplicitly use this filter with a BIO chain that can short-write and that\nwrite large, newline-free data influenced by an attacker would be affected.\nHowever, the circumstances where this could happen are unlikely to be under\nattacker control, and BIO_f_linebuffer is unlikely to be handling non-curated\ndata controlled by an attacker. For that reason the issue was assessed as\nLow severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the BIO implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."},{"id":"CVE-2025-69418","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4,"impactScore":2.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69418","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69418","date":"2026-10-08","epss":0.00129,"percentile":0.02225}],"urls":["https://github.com/openssl/openssl/commit/372fc5c77529695b05b4f5b5187691a57ef5dffc","https://github.com/openssl/openssl/commit/4016975d4469cd6b94927c607f7c511385f928d8","https://github.com/openssl/openssl/commit/52d23c86a54adab5ee9f80e48b242b52c4cc2347","https://github.com/openssl/openssl/commit/a7589230356d908c0eca4b969ec4f62106f4f5ae","https://github.com/openssl/openssl/commit/ed40856d7d4ba6cb42779b6770666a65f19cb977","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69418","description":"Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue."},{"id":"CVE-2025-69419","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69419","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69419","date":"2026-10-08","epss":0.00616,"percentile":0.47921}],"urls":["https://github.com/openssl/openssl/commit/41be0f216404f14457bbf3b9cc488dba60b49296","https://github.com/openssl/openssl/commit/7e9cac9832e4705b91987c2474ed06a37a93cecb","https://github.com/openssl/openssl/commit/a26a90d38edec3748566129d824e664b54bee2e2","https://github.com/openssl/openssl/commit/cda12de3bc0e333ea8d2c6fd15001dbdaf280015","https://github.com/openssl/openssl/commit/ff628933755075446bca8307e8417c14d164b535","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69419","description":"Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously\ncrafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing\nnon-ASCII BMP code point can trigger a one byte write before the allocated\nbuffer.\n\nImpact summary: The out-of-bounds write can cause a memory corruption\nwhich can have various consequences including a Denial of Service.\n\nThe OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12\nBMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes,\nthe helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16\nsource byte count as the destination buffer capacity to UTF8_putc(). For BMP\ncode points above U+07FF, UTF-8 requires three bytes, but the forwarded\ncapacity can be just two bytes. UTF8_putc() then returns -1, and this negative\nvalue is added to the output length without validation, causing the\nlength to become negative. The subsequent trailing NUL byte is then written\nat a negative offset, causing write outside of heap allocated buffer.\n\nThe vulnerability is reachable via the public PKCS12_get_friendlyname() API\nwhen parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a\ndifferent code path that avoids this issue, PKCS12_get_friendlyname() directly\ninvokes the vulnerable function. Exploitation requires an attacker to provide\na malicious PKCS#12 file to be parsed by the application and the attacker\ncan just trigger a one zero byte write before the allocated buffer.\nFor that reason the issue was assessed as Low severity according to our\nSecurity Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."},{"id":"CVE-2025-69420","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69420","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69420","date":"2026-10-08","epss":0.00899,"percentile":0.58405}],"urls":["https://github.com/openssl/openssl/commit/27c7012c91cc986a598d7540f3079dfde2416eb9","https://github.com/openssl/openssl/commit/4e254b48ad93cc092be3dd62d97015f33f73133a","https://github.com/openssl/openssl/commit/564fd9c73787f25693bf9e75faf7bf6bb1305d4e","https://github.com/openssl/openssl/commit/5eb0770ffcf11b785cf374ff3c19196245e54f1b","https://github.com/openssl/openssl/commit/a99349ebfc519999edc50620abe24d599b9eb085","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69420","description":"Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."},{"id":"CVE-2025-69421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69421","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69421","date":"2026-10-08","epss":0.00958,"percentile":0.60302}],"urls":["https://github.com/openssl/openssl/commit/3524a29271f8191b8fd8a5257eb05173982a097b","https://github.com/openssl/openssl/commit/36ecb4960872a4ce04bf6f1e1f4e78d75ec0c0c7","https://github.com/openssl/openssl/commit/4bbc8d41a72c842ce4077a8a3eccd1109aaf74bd","https://github.com/openssl/openssl/commit/643986985cd1c21221f941129d76fe0c2785aeb3","https://github.com/openssl/openssl/commit/a2dbc539f0f9cc63832709fa5aa33ad9495eb19c","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69421","description":"Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\n\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\n\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."},{"id":"CVE-2026-22795","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22795","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-22795","date":"2026-10-08","epss":0.00169,"percentile":0.0568}],"urls":["https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4","https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49","https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12","https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e","https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22795","description":"Issue summary: An invalid or NULL pointer dereference can happen in\nan application processing a malformed PKCS#12 file.\n\nImpact summary: An application processing a malformed PKCS#12 file can be\ncaused to dereference an invalid or NULL pointer on memory read, resulting\nin a Denial of Service.\n\nA type confusion vulnerability exists in PKCS#12 parsing code where\nan ASN1_TYPE union member is accessed without first validating the type,\ncausing an invalid pointer read.\n\nThe location is constrained to a 1-byte address space, meaning any\nattempted pointer manipulation can only target addresses between 0x00 and 0xFF.\nThis range corresponds to the zero page, which is unmapped on most modern\noperating systems and will reliably result in a crash, leading only to a\nDenial of Service. Exploiting this issue also requires a user or application\nto process a maliciously crafted PKCS#12 file. It is uncommon to accept\nuntrusted PKCS#12 files in applications as they are usually used to store\nprivate keys which are trusted by definition. For these reasons, the issue\nwas assessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."},{"id":"CVE-2026-22796","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22796","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-22796","date":"2026-10-08","epss":0.00576,"percentile":0.45751}],"urls":["https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4","https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49","https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12","https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e","https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22796","description":"Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4341","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4341","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"risk":1.7445,"urls":["https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736712","description":"The net/url package does not set a limit on the number of query parameters in a query.\n\nWhile the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61726","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"urls":["https://go.dev/cl/736712","https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4341","https://access.redhat.com/errata/RHSA-2026:10096","https://access.redhat.com/errata/RHSA-2026:10104","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:11408","https://access.redhat.com/errata/RHSA-2026:11414","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12279","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13542","https://access.redhat.com/errata/RHSA-2026:13548","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:15984","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17446","https://access.redhat.com/errata/RHSA-2026:17460","https://access.redhat.com/errata/RHSA-2026:17463","https://access.redhat.com/errata/RHSA-2026:17468","https://access.redhat.com/errata/RHSA-2026:17595","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:18913","https://access.redhat.com/errata/RHSA-2026:19013","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26420","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2706","https://access.redhat.com/errata/RHSA-2026:2708","https://access.redhat.com/errata/RHSA-2026:2709","https://access.redhat.com/errata/RHSA-2026:2754","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:2844","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:2914","https://access.redhat.com/errata/RHSA-2026:2920","https://access.redhat.com/errata/RHSA-2026:3035","https://access.redhat.com/errata/RHSA-2026:3040","https://access.redhat.com/errata/RHSA-2026:3089","https://access.redhat.com/errata/RHSA-2026:3092","https://access.redhat.com/errata/RHSA-2026:3184","https://access.redhat.com/errata/RHSA-2026:3186","https://access.redhat.com/errata/RHSA-2026:3187","https://access.redhat.com/errata/RHSA-2026:3188","https://access.redhat.com/errata/RHSA-2026:3192","https://access.redhat.com/errata/RHSA-2026:3193","https://access.redhat.com/errata/RHSA-2026:3291","https://access.redhat.com/errata/RHSA-2026:3296","https://access.redhat.com/errata/RHSA-2026:3297","https://access.redhat.com/errata/RHSA-2026:3298","https://access.redhat.com/errata/RHSA-2026:3336","https://access.redhat.com/errata/RHSA-2026:3337","https://access.redhat.com/errata/RHSA-2026:3340","https://access.redhat.com/errata/RHSA-2026:3341","https://access.redhat.com/errata/RHSA-2026:3343","https://access.redhat.com/errata/RHSA-2026:3391","https://access.redhat.com/errata/RHSA-2026:3416","https://access.redhat.com/errata/RHSA-2026:3427","https://access.redhat.com/errata/RHSA-2026:3459","https://access.redhat.com/errata/RHSA-2026:3468","https://access.redhat.com/errata/RHSA-2026:3469","https://access.redhat.com/errata/RHSA-2026:3470","https://access.redhat.com/errata/RHSA-2026:3471","https://access.redhat.com/errata/RHSA-2026:3472","https://access.redhat.com/errata/RHSA-2026:3473","https://access.redhat.com/errata/RHSA-2026:3489","https://access.redhat.com/errata/RHSA-2026:3506","https://access.redhat.com/errata/RHSA-2026:3556","https://access.redhat.com/errata/RHSA-2026:3559","https://access.redhat.com/errata/RHSA-2026:3668","https://access.redhat.com/errata/RHSA-2026:3669","https://access.redhat.com/errata/RHSA-2026:36873","https://access.redhat.com/errata/RHSA-2026:36882","https://access.redhat.com/errata/RHSA-2026:3699","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:3752","https://access.redhat.com/errata/RHSA-2026:3753","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3812","https://access.redhat.com/errata/RHSA-2026:3813","https://access.redhat.com/errata/RHSA-2026:3814","https://access.redhat.com/errata/RHSA-2026:3815","https://access.redhat.com/errata/RHSA-2026:3816","https://access.redhat.com/errata/RHSA-2026:3817","https://access.redhat.com/errata/RHSA-2026:3818","https://access.redhat.com/errata/RHSA-2026:3820","https://access.redhat.com/errata/RHSA-2026:3821","https://access.redhat.com/errata/RHSA-2026:3822","https://access.redhat.com/errata/RHSA-2026:3831","https://access.redhat.com/errata/RHSA-2026:3833","https://access.redhat.com/errata/RHSA-2026:3835","https://access.redhat.com/errata/RHSA-2026:3836","https://access.redhat.com/errata/RHSA-2026:3838","https://access.redhat.com/errata/RHSA-2026:3839","https://access.redhat.com/errata/RHSA-2026:3840","https://access.redhat.com/errata/RHSA-2026:3841","https://access.redhat.com/errata/RHSA-2026:3843","https://access.redhat.com/errata/RHSA-2026:3854","https://access.redhat.com/errata/RHSA-2026:3855","https://access.redhat.com/errata/RHSA-2026:3856","https://access.redhat.com/errata/RHSA-2026:3864","https://access.redhat.com/errata/RHSA-2026:3869","https://access.redhat.com/errata/RHSA-2026:3874","https://access.redhat.com/errata/RHSA-2026:3875","https://access.redhat.com/errata/RHSA-2026:3879","https://access.redhat.com/errata/RHSA-2026:3880","https://access.redhat.com/errata/RHSA-2026:3884","https://access.redhat.com/errata/RHSA-2026:3898","https://access.redhat.com/errata/RHSA-2026:3905","https://access.redhat.com/errata/RHSA-2026:3906","https://access.redhat.com/errata/RHSA-2026:3928","https://access.redhat.com/errata/RHSA-2026:3929","https://access.redhat.com/errata/RHSA-2026:3930","https://access.redhat.com/errata/RHSA-2026:3931","https://access.redhat.com/errata/RHSA-2026:3932","https://access.redhat.com/errata/RHSA-2026:3958","https://access.redhat.com/errata/RHSA-2026:3959","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:3970","https://access.redhat.com/errata/RHSA-2026:3971","https://access.redhat.com/errata/RHSA-2026:3972","https://access.redhat.com/errata/RHSA-2026:3973","https://access.redhat.com/errata/RHSA-2026:3974","https://access.redhat.com/errata/RHSA-2026:3977","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:3985","https://access.redhat.com/errata/RHSA-2026:40924","https://access.redhat.com/errata/RHSA-2026:4164","https://access.redhat.com/errata/RHSA-2026:4166","https://access.redhat.com/errata/RHSA-2026:4170","https://access.redhat.com/errata/RHSA-2026:4174","https://access.redhat.com/errata/RHSA-2026:4177","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41941","https://access.redhat.com/errata/RHSA-2026:4211","https://access.redhat.com/errata/RHSA-2026:4220","https://access.redhat.com/errata/RHSA-2026:4256","https://access.redhat.com/errata/RHSA-2026:4264","https://access.redhat.com/errata/RHSA-2026:4267","https://access.redhat.com/errata/RHSA-2026:4270","https://access.redhat.com/errata/RHSA-2026:4276","https://access.redhat.com/errata/RHSA-2026:4434","https://access.redhat.com/errata/RHSA-2026:4435","https://access.redhat.com/errata/RHSA-2026:4460","https://access.redhat.com/errata/RHSA-2026:4466","https://access.redhat.com/errata/RHSA-2026:4467","https://access.redhat.com/errata/RHSA-2026:4498","https://access.redhat.com/errata/RHSA-2026:4500","https://access.redhat.com/errata/RHSA-2026:4510","https://access.redhat.com/errata/RHSA-2026:4511","https://access.redhat.com/errata/RHSA-2026:4672","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:4753","https://access.redhat.com/errata/RHSA-2026:4892","https://access.redhat.com/errata/RHSA-2026:4901","https://access.redhat.com/errata/RHSA-2026:4907","https://access.redhat.com/errata/RHSA-2026:4939","https://access.redhat.com/errata/RHSA-2026:4942","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:4952","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5022","https://access.redhat.com/errata/RHSA-2026:5030","https://access.redhat.com/errata/RHSA-2026:5031","https://access.redhat.com/errata/RHSA-2026:5076","https://access.redhat.com/errata/RHSA-2026:5077","https://access.redhat.com/errata/RHSA-2026:5078","https://access.redhat.com/errata/RHSA-2026:5079","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:5129","https://access.redhat.com/errata/RHSA-2026:5130","https://access.redhat.com/errata/RHSA-2026:5131","https://access.redhat.com/errata/RHSA-2026:5132","https://access.redhat.com/errata/RHSA-2026:5145","https://access.redhat.com/errata/RHSA-2026:5146","https://access.redhat.com/errata/RHSA-2026:5168","https://access.redhat.com/errata/RHSA-2026:5327","https://access.redhat.com/errata/RHSA-2026:5394","https://access.redhat.com/errata/RHSA-2026:5439","https://access.redhat.com/errata/RHSA-2026:5444","https://access.redhat.com/errata/RHSA-2026:5447","https://access.redhat.com/errata/RHSA-2026:5452","https://access.redhat.com/errata/RHSA-2026:5461","https://access.redhat.com/errata/RHSA-2026:5463","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5533","https://access.redhat.com/errata/RHSA-2026:5544","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:5636","https://access.redhat.com/errata/RHSA-2026:56366","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:5645","https://access.redhat.com/errata/RHSA-2026:5649","https://access.redhat.com/errata/RHSA-2026:5665","https://access.redhat.com/errata/RHSA-2026:57013","https://access.redhat.com/errata/RHSA-2026:5807","https://access.redhat.com/errata/RHSA-2026:5851","https://access.redhat.com/errata/RHSA-2026:5852","https://access.redhat.com/errata/RHSA-2026:5853","https://access.redhat.com/errata/RHSA-2026:5948","https://access.redhat.com/errata/RHSA-2026:5950","https://access.redhat.com/errata/RHSA-2026:5952","https://access.redhat.com/errata/RHSA-2026:5968","https://access.redhat.com/errata/RHSA-2026:6184","https://access.redhat.com/errata/RHSA-2026:6192","https://access.redhat.com/errata/RHSA-2026:6226","https://access.redhat.com/errata/RHSA-2026:6251","https://access.redhat.com/errata/RHSA-2026:6277","https://access.redhat.com/errata/RHSA-2026:6278","https://access.redhat.com/errata/RHSA-2026:6428","https://access.redhat.com/errata/RHSA-2026:6429","https://access.redhat.com/errata/RHSA-2026:6497","https://access.redhat.com/errata/RHSA-2026:6554","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:6567","https://access.redhat.com/errata/RHSA-2026:6568","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:7052","https://access.redhat.com/errata/RHSA-2026:7249","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7676","https://access.redhat.com/errata/RHSA-2026:7854","https://access.redhat.com/errata/RHSA-2026:7942","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8218","https://access.redhat.com/errata/RHSA-2026:8229","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8431","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9848","https://access.redhat.com/security/cve/CVE-2025-61726","https://bugzilla.redhat.com/show_bug.cgi?id=2434432","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61726","description":"The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4337","versionConstraint":"<1.24.13||>=1.25.0-0,<1.25.7||>=1.26.0-rc.1,<1.26.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4337","fix":{"state":"fixed","versions":["1.24.13","1.25.7","1.26.0-rc.3"],"available":[{"date":"2026-02-04","kind":"release","version":"1.24.13"},{"date":"2026-02-04","kind":"release","version":"1.25.7"},{"date":"2026-02-04","kind":"release","version":"1.26.0-rc.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"risk":0.8692500000000001,"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-68121","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217","https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","https://pkg.go.dev/vuln/GO-2026-4337"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68121","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."}]},{"artifact":{"id":"f02d56b67963eac2","cpes":["cpe:2.3:a:oracleamerica:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:gnutls:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/ol/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=ol-9.8&upstream=gnutls-3.8.10-8.el9_8.src.rpm","type":"rpm","version":"3.8.10-8.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.7.6-23.el9_3.4_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2024-12336","versionConstraint":"< 10:3.7.6-23.el9_3.4_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-8.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2024-12336","fix":{"state":"fixed","versions":["10:3.7.6-23.el9_3.4_fips"],"available":[{"date":"2024-04-19","kind":"advisory","version":"10:3.7.6-23.el9_3.4_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2024-0553","cwe":"CWE-203","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-0553","cwe":"CWE-203","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2024-28835","cwe":"CWE-248","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-0567","cwe":"CWE-347","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-0567","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-28834","cwe":"CWE-327","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-5981","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-5981","cwe":"CWE-203","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-0553","date":"2026-10-08","epss":0.01614,"percentile":0.75252},{"cve":"CVE-2024-28835","date":"2026-10-08","epss":0.00389,"percentile":0.30895},{"cve":"CVE-2024-0567","date":"2026-10-08","epss":0.0142,"percentile":0.7202},{"cve":"CVE-2024-28834","date":"2026-10-08","epss":0.00724,"percentile":0.52616},{"cve":"CVE-2023-5981","date":"2026-10-08","epss":0.01267,"percentile":0.68897}],"risk":0.807,"urls":["https://linux.oracle.com/cve/CVE-2024-0553.html","https://linux.oracle.com/cve/CVE-2024-28835.html","https://linux.oracle.com/cve/CVE-2024-0567.html","https://linux.oracle.com/cve/CVE-2024-28834.html","https://linux.oracle.com/cve/CVE-2023-5981.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2024-12336.html","description":"[3.7.6-23.4_fips]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35925409]\n- Update FIPS module name for Oracle Linux [Orabug: 35925409]\n- Verify salt length and iteration count for PBKDF [Orabug: 35925409]\n\n[3.7.6-23.4]\n- Fix timing side-channel in deterministic ECDSA (RHEL-28958)\n- Fix potential crash during chain building/verification (RHEL-28953)\n\n[3.7.6-23.3]\n- x509: detect loop in certificate chain (RHEL-21759)\n- fips: Zeroize temporary values in integrity check (RHEL-21870)\n\n[3.7.6-23.2]\n- auth/rsa_psk: minimize branching after decryption\n\n[3.7.6-23.1]\n- auth/rsa_psk: side-step potential side-channel (RHEL-16755)\n\n[3.7.6-23]\n- Mark SHA-1 signature verification non-approved in FIPS (#2102751)\n\n[3.7.6-22]\n- Skip KTLS test on old kernel if host and target arches are different"},"relatedVulnerabilities":[{"id":"CVE-2024-0553","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0553","cwe":"CWE-203","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-0553","cwe":"CWE-203","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-0553","date":"2026-10-08","epss":0.01614,"percentile":0.75252}],"urls":["https://access.redhat.com/errata/RHSA-2024:0533","https://access.redhat.com/errata/RHSA-2024:0627","https://access.redhat.com/errata/RHSA-2024:0796","https://access.redhat.com/errata/RHSA-2024:1082","https://access.redhat.com/errata/RHSA-2024:1108","https://access.redhat.com/errata/RHSA-2024:1383","https://access.redhat.com/errata/RHSA-2024:2094","https://access.redhat.com/security/cve/CVE-2024-0553","https://bugzilla.redhat.com/show_bug.cgi?id=2258412","https://gitlab.com/gnutls/gnutls/-/issues/1522","https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html","http://www.openwall.com/lists/oss-security/2024/01/19/3","https://lists.debian.org/debian-lts-announce/2024/02/msg00010.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNXKVR5YNUEBNHAHM5GSYKBZX4W2HMN2/","https://security.netapp.com/advisory/ntap-20240202-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0553","description":"A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981."},{"id":"CVE-2024-28835","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28835","cwe":"CWE-248","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-28835","date":"2026-10-08","epss":0.00389,"percentile":0.30895}],"urls":["https://access.redhat.com/errata/RHSA-2024:1879","https://access.redhat.com/errata/RHSA-2024:2570","https://access.redhat.com/errata/RHSA-2024:2889","https://access.redhat.com/security/cve/CVE-2024-28835","https://bugzilla.redhat.com/show_bug.cgi?id=2269084","https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html","http://www.openwall.com/lists/oss-security/2024/03/22/1","http://www.openwall.com/lists/oss-security/2024/03/22/2","https://lists.debian.org/debian-lts-announce/2024/09/msg00019.html","https://security.netapp.com/advisory/ntap-20241122-0009/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28835","description":"A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the \"certtool --verify-chain\" command."},{"id":"CVE-2024-0567","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0567","cwe":"CWE-347","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-0567","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-0567","date":"2026-10-08","epss":0.0142,"percentile":0.7202}],"urls":["https://access.redhat.com/errata/RHSA-2024:0533","https://access.redhat.com/errata/RHSA-2024:1082","https://access.redhat.com/errata/RHSA-2024:1383","https://access.redhat.com/errata/RHSA-2024:2094","https://access.redhat.com/security/cve/CVE-2024-0567","https://bugzilla.redhat.com/show_bug.cgi?id=2258544","https://gitlab.com/gnutls/gnutls/-/issues/1521","https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html","http://www.openwall.com/lists/oss-security/2024/01/19/3","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNXKVR5YNUEBNHAHM5GSYKBZX4W2HMN2/","https://security.netapp.com/advisory/ntap-20240202-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0567","description":"A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack."},{"id":"CVE-2024-28834","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28834","cwe":"CWE-327","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-28834","date":"2026-10-08","epss":0.00724,"percentile":0.52616}],"urls":["https://access.redhat.com/errata/RHSA-2024:1784","https://access.redhat.com/errata/RHSA-2024:1879","https://access.redhat.com/errata/RHSA-2024:1997","https://access.redhat.com/errata/RHSA-2024:2044","https://access.redhat.com/errata/RHSA-2024:2570","https://access.redhat.com/errata/RHSA-2024:2889","https://access.redhat.com/security/cve/CVE-2024-28834","https://bugzilla.redhat.com/show_bug.cgi?id=2269228","https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html","https://minerva.crocs.fi.muni.cz/","http://www.openwall.com/lists/oss-security/2024/03/22/1","http://www.openwall.com/lists/oss-security/2024/03/22/2","https://lists.debian.org/debian-lts-announce/2024/09/msg00019.html","https://people.redhat.com/~hkario/marvin/","https://security.netapp.com/advisory/ntap-20240524-0004/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28834","description":"A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel."},{"id":"CVE-2023-5981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-5981","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-5981","cwe":"CWE-203","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5981","date":"2026-10-08","epss":0.01267,"percentile":0.68897}],"urls":["https://access.redhat.com/errata/RHSA-2024:0155","https://access.redhat.com/errata/RHSA-2024:0319","https://access.redhat.com/errata/RHSA-2024:0399","https://access.redhat.com/errata/RHSA-2024:0451","https://access.redhat.com/errata/RHSA-2024:0533","https://access.redhat.com/errata/RHSA-2024:1383","https://access.redhat.com/errata/RHSA-2024:2094","https://access.redhat.com/security/cve/CVE-2023-5981","https://bugzilla.redhat.com/show_bug.cgi?id=2248445","https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23","http://www.openwall.com/lists/oss-security/2024/01/19/3","https://lists.debian.org/debian-lts-announce/2023/11/msg00016.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNXKVR5YNUEBNHAHM5GSYKBZX4W2HMN2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5981","description":"A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding."}]},{"artifact":{"id":"cf3f4f305e651dab","cpes":["cpe:2.3:a:oracleamerica:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/ol/openssl@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.5.1-4.0.2.el9_7_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2025-28011","versionConstraint":"< 10:3.5.1-4.0.2.el9_7_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2025-28011","fix":{"state":"fixed","versions":["10:3.5.1-4.0.2.el9_7_fips"],"available":[{"date":"2025-11-25","kind":"advisory","version":"10:3.5.1-4.0.2.el9_7_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-9230","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-9230","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9230","date":"2026-10-08","epss":0.01554,"percentile":0.74399}],"risk":0.777,"urls":["https://linux.oracle.com/cve/CVE-2025-9230.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2025-28011.html","description":"[3.5.1-4.0.2_fips]\n- Update additional upstream references\n\n[3.5.1-4.0.1_fips]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name [Orabug: 35824276]\n\n[3.5.1-4.0.1]\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[3.5.1.openela.0.1]\n- Add OpenELA specific changes\n\n[1:3.5.1-4]\n- Fix CVE-2025-9230\n  Resolves: RHEL-115929\n\n[1:3.5.1-3]\n- Add custom define to disable symbol versioning in downstream patched code\n  Also add stricter Suggests for openssl-fips-provider\n  Resolves: RHEL-104236\n- Fix Requires/Provider to fix default install of fips providers\n  Resolves: RHEL-104856\n\n[1:3.5.1-2]\n- Move fips.so to a seprate subpackage\n  Reverts FIPS self test for SLH-DSA\n  Add Suggests to try to prefer the openssl-fips-provider package\n  over the fips-provider-next package by default\n  Revolves: RHEL-102408\n  Related: RHEL-80854\n\n[1:3.5.1-1]\n- Rebasing to OpenSSL 3.5.1\n  Resolves: RHEL-97797\n  Resolves: RHEL-98723\n  Resolves: RHEL-99352\n\n[1:3.5.0-4]\n- Compact patches for better maintainability\n  Related: RHEL-80854\n- Make hybrid MLKEM work with our FIPS provider (3.0.7)\n  Resolves: RHEL-95239\n\n[1:3.5.0-3]\n- Fix regressions caused by rebase to OpenSSL 3.5\n  Related: RHEL-80854"},"relatedVulnerabilities":[{"id":"CVE-2025-9230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9230","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-9230","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9230","date":"2026-10-08","epss":0.01554,"percentile":0.74399}],"urls":["https://github.com/openssl/openssl/commit/5965ea5dd6960f36d8b7f74f8eac67a8eb8f2b45","https://github.com/openssl/openssl/commit/9e91358f365dee6c446dcdcdb01c04d2743fd280","https://github.com/openssl/openssl/commit/a79c4ce559c6a3a8fd4109e9f33c1185d5bf2def","https://github.com/openssl/openssl/commit/b5282d677551afda7d20e9c00e09561b547b2dfd","https://github.com/openssl/openssl/commit/bae259a211ada6315dc50900686daaaaaa55f482","https://github.openssl.org/openssl/extended-releases/commit/c2b96348bfa662f25f4fabf81958ae822063dae3","https://github.openssl.org/openssl/extended-releases/commit/dfbaf161d8dafc1132dd88cd48ad990ed9b4c8ba","https://openssl-library.org/news/secadv/20250930.txt","http://www.openwall.com/lists/oss-security/2025/09/30/5","https://lists.debian.org/debian-lts-announce/2025/10/msg00001.html","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9230","description":"Issue summary: An application trying to decrypt CMS messages encrypted using\npassword based encryption can trigger an out-of-bounds read and write.\n\nImpact summary: This out-of-bounds read may trigger a crash which leads to\nDenial of Service for an application. The out-of-bounds write can cause\na memory corruption which can have various consequences including\na Denial of Service or Execution of attacker-supplied code.\n\nAlthough the consequences of a successful exploit of this vulnerability\ncould be severe, the probability that the attacker would be able to\nperform it is low. Besides, password based (PWRI) encryption support in CMS\nmessages is very rarely used. For that reason the issue was assessed as\nModerate severity according to our Security Policy.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"dfd591701b2bf27b","cpes":["cpe:2.3:a:oracleamerica:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:oracleamerica:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/ol/openssl-libs@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.0.1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.5.1-4.0.2.el9_7_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2025-28011","versionConstraint":"< 10:3.5.1-4.0.2.el9_7_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl-libs","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2025-28011","fix":{"state":"fixed","versions":["10:3.5.1-4.0.2.el9_7_fips"],"available":[{"date":"2025-11-25","kind":"advisory","version":"10:3.5.1-4.0.2.el9_7_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-9230","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-9230","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9230","date":"2026-10-08","epss":0.01554,"percentile":0.74399}],"risk":0.777,"urls":["https://linux.oracle.com/cve/CVE-2025-9230.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2025-28011.html","description":"[3.5.1-4.0.2_fips]\n- Update additional upstream references\n\n[3.5.1-4.0.1_fips]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name [Orabug: 35824276]\n\n[3.5.1-4.0.1]\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[3.5.1.openela.0.1]\n- Add OpenELA specific changes\n\n[1:3.5.1-4]\n- Fix CVE-2025-9230\n  Resolves: RHEL-115929\n\n[1:3.5.1-3]\n- Add custom define to disable symbol versioning in downstream patched code\n  Also add stricter Suggests for openssl-fips-provider\n  Resolves: RHEL-104236\n- Fix Requires/Provider to fix default install of fips providers\n  Resolves: RHEL-104856\n\n[1:3.5.1-2]\n- Move fips.so to a seprate subpackage\n  Reverts FIPS self test for SLH-DSA\n  Add Suggests to try to prefer the openssl-fips-provider package\n  over the fips-provider-next package by default\n  Revolves: RHEL-102408\n  Related: RHEL-80854\n\n[1:3.5.1-1]\n- Rebasing to OpenSSL 3.5.1\n  Resolves: RHEL-97797\n  Resolves: RHEL-98723\n  Resolves: RHEL-99352\n\n[1:3.5.0-4]\n- Compact patches for better maintainability\n  Related: RHEL-80854\n- Make hybrid MLKEM work with our FIPS provider (3.0.7)\n  Resolves: RHEL-95239\n\n[1:3.5.0-3]\n- Fix regressions caused by rebase to OpenSSL 3.5\n  Related: RHEL-80854"},"relatedVulnerabilities":[{"id":"CVE-2025-9230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9230","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-9230","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9230","date":"2026-10-08","epss":0.01554,"percentile":0.74399}],"urls":["https://github.com/openssl/openssl/commit/5965ea5dd6960f36d8b7f74f8eac67a8eb8f2b45","https://github.com/openssl/openssl/commit/9e91358f365dee6c446dcdcdb01c04d2743fd280","https://github.com/openssl/openssl/commit/a79c4ce559c6a3a8fd4109e9f33c1185d5bf2def","https://github.com/openssl/openssl/commit/b5282d677551afda7d20e9c00e09561b547b2dfd","https://github.com/openssl/openssl/commit/bae259a211ada6315dc50900686daaaaaa55f482","https://github.openssl.org/openssl/extended-releases/commit/c2b96348bfa662f25f4fabf81958ae822063dae3","https://github.openssl.org/openssl/extended-releases/commit/dfbaf161d8dafc1132dd88cd48ad990ed9b4c8ba","https://openssl-library.org/news/secadv/20250930.txt","http://www.openwall.com/lists/oss-security/2025/09/30/5","https://lists.debian.org/debian-lts-announce/2025/10/msg00001.html","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9230","description":"Issue summary: An application trying to decrypt CMS messages encrypted using\npassword based encryption can trigger an out-of-bounds read and write.\n\nImpact summary: This out-of-bounds read may trigger a crash which leads to\nDenial of Service for an application. The out-of-bounds write can cause\na memory corruption which can have various consequences including\na Denial of Service or Execution of attacker-supplied code.\n\nAlthough the consequences of a successful exploit of this vulnerability\ncould be severe, the probability that the attacker would be able to\nperform it is low. Besides, password based (PWRI) encryption support in CMS\nmessages is very rarely used. For that reason the issue was assessed as\nModerate severity according to our Security Policy.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"f02d56b67963eac2","cpes":["cpe:2.3:a:oracleamerica:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:gnutls:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/ol/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=ol-9.8&upstream=gnutls-3.8.10-8.el9_8.src.rpm","type":"rpm","version":"3.8.10-8.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.8.3-6.el9_6.2_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2025-20606","versionConstraint":"< 10:3.8.3-6.el9_6.2_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-8.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2025-20606","fix":{"state":"fixed","versions":["10:3.8.3-6.el9_6.2_fips"],"available":[{"date":"2025-09-19","kind":"advisory","version":"10:3.8.3-6.el9_6.2_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-32988","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2025-6395","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2025-32989","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2025-32990","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-32988","date":"2026-10-08","epss":0.01373,"percentile":0.71137},{"cve":"CVE-2025-6395","date":"2026-10-08","epss":0.00717,"percentile":0.52395},{"cve":"CVE-2025-32989","date":"2026-10-08","epss":0.01366,"percentile":0.7099},{"cve":"CVE-2025-32990","date":"2026-10-08","epss":0.00834,"percentile":0.56371}],"risk":0.6865,"urls":["https://linux.oracle.com/cve/CVE-2025-32988.html","https://linux.oracle.com/cve/CVE-2025-6395.html","https://linux.oracle.com/cve/CVE-2025-32989.html","https://linux.oracle.com/cve/CVE-2025-32990.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2025-20606.html","description":"[3.8.3-6.2_fips]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35925409]\n- Update FIPS module name for Oracle Linux [Orabug: 35925409]\n\n[3.8.3-6.2]\n- key_update: rework the rekeying logic (RHEL-107498)\n\n[3.8.3-6.1]\n- Fix CVE-2025-32988, CVE-2025-32989, CVE-2025-32990, and CVE-2025-6395"},"relatedVulnerabilities":[{"id":"CVE-2025-32988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32988","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-32988","date":"2026-10-08","epss":0.01373,"percentile":0.71137}],"urls":["https://access.redhat.com/errata/RHSA-2025:16115","https://access.redhat.com/errata/RHSA-2025:16116","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:17348","https://access.redhat.com/errata/RHSA-2025:17361","https://access.redhat.com/errata/RHSA-2025:17415","https://access.redhat.com/errata/RHSA-2025:19088","https://access.redhat.com/errata/RHSA-2025:22529","https://access.redhat.com/errata/RHSA-2026:7477","https://access.redhat.com/security/cve/CVE-2025-32988","https://bugzilla.redhat.com/show_bug.cgi?id=2359622","https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html","http://www.openwall.com/lists/oss-security/2025/07/11/3","https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-32988","description":"A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.\n\nThis vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior."},{"id":"CVE-2025-6395","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6395","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6395","date":"2026-10-08","epss":0.00717,"percentile":0.52395}],"urls":["https://access.redhat.com/errata/RHSA-2025:16115","https://access.redhat.com/errata/RHSA-2025:16116","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:17348","https://access.redhat.com/errata/RHSA-2025:17361","https://access.redhat.com/errata/RHSA-2025:17415","https://access.redhat.com/errata/RHSA-2025:19088","https://access.redhat.com/errata/RHSA-2025:22529","https://access.redhat.com/security/cve/CVE-2025-6395","https://bugzilla.redhat.com/show_bug.cgi?id=2376755","https://gitlab.com/gnutls/gnutls/-/issues/1718","https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html","http://www.openwall.com/lists/oss-security/2025/07/11/3","https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6395","description":"A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite()."},{"id":"CVE-2025-32989","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32989","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-32989","date":"2026-10-08","epss":0.01366,"percentile":0.7099}],"urls":["https://access.redhat.com/errata/RHSA-2025:16115","https://access.redhat.com/errata/RHSA-2025:16116","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:17348","https://access.redhat.com/errata/RHSA-2025:17361","https://access.redhat.com/errata/RHSA-2025:19088","https://access.redhat.com/errata/RHSA-2025:22529","https://access.redhat.com/errata/RHSA-2026:7477","https://access.redhat.com/security/cve/CVE-2025-32989","https://bugzilla.redhat.com/show_bug.cgi?id=2359621","https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html","http://www.openwall.com/lists/oss-security/2025/07/11/3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-32989","description":"A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly."},{"id":"CVE-2025-32990","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32990","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-32990","date":"2026-10-08","epss":0.00834,"percentile":0.56371}],"urls":["https://access.redhat.com/errata/RHSA-2025:16115","https://access.redhat.com/errata/RHSA-2025:16116","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:17348","https://access.redhat.com/errata/RHSA-2025:17361","https://access.redhat.com/errata/RHSA-2025:17415","https://access.redhat.com/errata/RHSA-2025:19088","https://access.redhat.com/errata/RHSA-2025:22529","https://access.redhat.com/errata/RHSA-2026:7477","https://access.redhat.com/security/cve/CVE-2025-32990","https://bugzilla.redhat.com/show_bug.cgi?id=2359620","https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html","http://www.openwall.com/lists/oss-security/2025/07/11/3","https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-32990","description":"A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system."}]},{"artifact":{"id":"f02d56b67963eac2","cpes":["cpe:2.3:a:oracleamerica:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:gnutls:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/ol/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=ol-9.8&upstream=gnutls-3.8.10-8.el9_8.src.rpm","type":"rpm","version":"3.8.10-8.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.8.10-4.el9_8_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-50346","versionConstraint":"< 10:3.8.10-4.el9_8_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-8.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-50346","fix":{"state":"fixed","versions":["10:3.8.10-4.el9_8_fips"],"available":[{"date":"2026-06-24","kind":"advisory","version":"10:3.8.10-4.el9_8_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"cve":"CVE-2026-3832","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-3833","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42010","cwe":"CWE-626","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"cve":"CVE-2026-42011","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42012","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42013","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42014","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42015","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-5260","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-5419","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-33845","date":"2026-10-08","epss":0.00886,"percentile":0.58022},{"cve":"CVE-2026-33846","date":"2026-10-08","epss":0.01123,"percentile":0.65216},{"cve":"CVE-2026-3832","date":"2026-10-08","epss":0.0085,"percentile":0.56912},{"cve":"CVE-2026-3833","date":"2026-10-08","epss":0.00892,"percentile":0.58203},{"cve":"CVE-2026-42009","date":"2026-10-08","epss":0.01129,"percentile":0.65367},{"cve":"CVE-2026-42010","date":"2026-10-08","epss":0.00944,"percentile":0.59864},{"cve":"CVE-2026-42011","date":"2026-10-08","epss":0.0057,"percentile":0.45419},{"cve":"CVE-2026-42012","date":"2026-10-08","epss":0.00487,"percentile":0.3999},{"cve":"CVE-2026-42013","date":"2026-10-08","epss":0.00564,"percentile":0.45129},{"cve":"CVE-2026-42014","date":"2026-10-08","epss":0.002,"percentile":0.09032},{"cve":"CVE-2026-42015","date":"2026-10-08","epss":0.0092,"percentile":0.59061},{"cve":"CVE-2026-5260","date":"2026-10-08","epss":0.00945,"percentile":0.59888},{"cve":"CVE-2026-5419","date":"2026-10-08","epss":0.0063,"percentile":0.48546}],"risk":0.6645,"urls":["https://linux.oracle.com/cve/CVE-2026-33845.html","https://linux.oracle.com/cve/CVE-2026-33846.html","https://linux.oracle.com/cve/CVE-2026-3832.html","https://linux.oracle.com/cve/CVE-2026-3833.html","https://linux.oracle.com/cve/CVE-2026-42009.html","https://linux.oracle.com/cve/CVE-2026-42010.html","https://linux.oracle.com/cve/CVE-2026-42011.html","https://linux.oracle.com/cve/CVE-2026-42012.html","https://linux.oracle.com/cve/CVE-2026-42013.html","https://linux.oracle.com/cve/CVE-2026-42014.html","https://linux.oracle.com/cve/CVE-2026-42015.html","https://linux.oracle.com/cve/CVE-2026-5260.html","https://linux.oracle.com/cve/CVE-2026-5419.html"],"severity":"High","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-50346.html","description":"[3.8.10-4_fips]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35925409]\n- Update FIPS module name for Oracle Linux [Orabug: 35925409]\n\n[3.8.10-4]\n- Fix CVE-2026-33846 (DTLS fragment reassembly, High, heap overwrite)\n- Fix CVE-2026-42009 (DTLS fragment reassembly, High, undefined behaviour)\n- Fix CVE-2026-33845 (DTLS fragment reassembly, High, heap overread)\n- Fix CVE-2026-42010 (PSK authentication, High, authentication bypass)\n- Fix CVE-2026-3833 (Name constraints, Medium, name constraint bypass)\n- Fix CVE-2026-42011 (Name constraints, Medium, name constraint bypass)\n- Fix CVE-2026-42012 (CN fallback, Medium, certificate misuse)\n- Fix CVE-2026-42013 (CN fallback, Medium, certificate misuse)\n- Fix CVE-2026-42014 (PKCS#11 PIN change, Medium, use-after-free)\n- Fix CVE-2026-5260 (PKCS#11 RSA, Medium, heap overread)\n- Fix CVE-2026-42015 (PKCS#12 appending, Low, heap overwrite)\n- Fix CVE-2026-3832 (OCSP, Low, revocation bypass)\n- Fix CVE-2026-5419 (PKCS#7, Low, timing side-channel)\n- Fix upstream security issue #1808 (PSK rehandshake)\n- Fix upstream security issue #1810 (EKU OID prefix match)\n- Fix upstream security issue #1813 (pkcs11-provider persistent keys)\n- Fix upstream security issue #1818 (RSA correctness, OpenSSL format import)\n- Fix upstream security issue #1819 (PKCS#11 trust removal error path)\n- Fix upstream security issue #1822 (SCT extension parser OOB read)\n- Fix upstream security issue #1841 (key zeroization in hybrid kex)\n- Fix upstream security issue #1823 (malformed certtool template)\n- Fix upstream security issue #1817 (session parameter loading robustness)\n- Fix upstream security issue #1820 (PKCS#11 KDF succeeding w/o deriving)\n- gnutls-3.8.10-CVE-2025-9820.patch: update Makefile.in\n\n[3.8.10-3]\n- Fix PKCS#11 token initialization label overflow (CVE-2025-9820)\n- Fix name constraint processing performance issue (CVE-2025-14831)\n\n[3.8.10-2]\n- Reinstate and update the prematurely dropped rekeying patch\n\n[3.8.10-1]\n- Rebase to 3.8.10\n- Revert defaulting to PBMAC1 in FIPS mode\n- Revert unapproving 1024-, 1280-, 1536- and 1792-bit RSA verification"},"relatedVulnerabilities":[{"id":"CVE-2026-33845","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33845","date":"2026-10-08","epss":0.00886,"percentile":0.58022}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-33845","https://bugzilla.redhat.com/show_bug.cgi?id=2450624","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33845.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33845","description":"A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service."},{"id":"CVE-2026-33846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33846","date":"2026-10-08","epss":0.01123,"percentile":0.65216}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-33846","https://bugzilla.redhat.com/show_bug.cgi?id=2450625","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33846","description":"A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption."},{"id":"CVE-2026-3832","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3832","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3832","date":"2026-10-08","epss":0.0085,"percentile":0.56912}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-3832","https://bugzilla.redhat.com/show_bug.cgi?id=2445762","https://gitlab.com/gnutls/gnutls/-/issues/1801"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3832","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust."},{"id":"CVE-2026-3833","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3833","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3833","date":"2026-10-08","epss":0.00892,"percentile":0.58203}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-3833","https://bugzilla.redhat.com/show_bug.cgi?id=2445763","https://gitlab.com/gnutls/gnutls/-/issues/1803"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3833","description":"A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure."},{"id":"CVE-2026-42009","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42009","date":"2026-10-08","epss":0.01129,"percentile":0.65367}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:29794","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:34764","https://access.redhat.com/errata/RHSA-2026:34788","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42009","https://bugzilla.redhat.com/show_bug.cgi?id=2467279","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42009","description":"A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service."},{"id":"CVE-2026-42010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42010","cwe":"CWE-626","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42010","date":"2026-10-08","epss":0.00944,"percentile":0.59864}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34764","https://access.redhat.com/errata/RHSA-2026:34788","https://access.redhat.com/errata/RHSA-2026:34790","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42010","https://bugzilla.redhat.com/show_bug.cgi?id=2467289","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42010","description":"A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process."},{"id":"CVE-2026-42011","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42011","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42011","date":"2026-10-08","epss":0.0057,"percentile":0.45419}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42011","https://bugzilla.redhat.com/show_bug.cgi?id=2467437","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42011","description":"A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems."},{"id":"CVE-2026-42012","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42012","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42012","date":"2026-10-08","epss":0.00487,"percentile":0.3999}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42012","https://bugzilla.redhat.com/show_bug.cgi?id=2467441","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42012","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information."},{"id":"CVE-2026-42013","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42013","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42013","date":"2026-10-08","epss":0.00564,"percentile":0.45129}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42013","https://bugzilla.redhat.com/show_bug.cgi?id=2467448","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42013","description":"A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks."},{"id":"CVE-2026-42014","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42014","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42014","date":"2026-10-08","epss":0.002,"percentile":0.09032}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42014","https://bugzilla.redhat.com/show_bug.cgi?id=2467451","https://gitlab.com/gnutls/gnutls/-/issues/1766","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42014","description":"A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path."},{"id":"CVE-2026-42015","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42015","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42015","date":"2026-10-08","epss":0.0092,"percentile":0.59061}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42015","https://bugzilla.redhat.com/show_bug.cgi?id=2467678","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42015","description":"A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts."},{"id":"CVE-2026-5260","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5260","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5260","date":"2026-10-08","epss":0.00945,"percentile":0.59888}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:67837","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-5260","https://bugzilla.redhat.com/show_bug.cgi?id=2467450","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5260","description":"A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure."},{"id":"CVE-2026-5419","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5419","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5419","date":"2026-10-08","epss":0.0063,"percentile":0.48546}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-5419","https://bugzilla.redhat.com/show_bug.cgi?id=2467686","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5419","description":"A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure."}]},{"artifact":{"id":"cf3f4f305e651dab","cpes":["cpe:2.3:a:oracleamerica:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/ol/openssl@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.5.5-4.0.1.el9_8_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-50379","versionConstraint":"< 10:3.5.5-4.0.1.el9_8_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-50379","fix":{"state":"fixed","versions":["10:3.5.5-4.0.1.el9_8_fips"],"available":[{"date":"2026-07-07","kind":"advisory","version":"10:3.5.5-4.0.1.el9_8_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-34181","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-34183","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42764","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42768","cwe":"CWE-514","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42769","cwe":"CWE-295","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792},{"cve":"CVE-2026-34181","date":"2026-10-08","epss":0.00182,"percentile":0.07141},{"cve":"CVE-2026-34182","date":"2026-10-08","epss":0.01057,"percentile":0.63405},{"cve":"CVE-2026-34183","date":"2026-10-08","epss":0.01049,"percentile":0.63201},{"cve":"CVE-2026-42764","date":"2026-10-08","epss":0.00778,"percentile":0.5448},{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898},{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852},{"cve":"CVE-2026-42768","date":"2026-10-08","epss":0.00295,"percentile":0.20305},{"cve":"CVE-2026-42769","date":"2026-10-08","epss":0.00239,"percentile":0.13688},{"cve":"CVE-2026-42770","date":"2026-10-08","epss":0.00258,"percentile":0.16004},{"cve":"CVE-2026-45445","date":"2026-10-08","epss":0.00704,"percentile":0.51865},{"cve":"CVE-2026-45446","date":"2026-10-08","epss":0.00236,"percentile":0.13414},{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276},{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746},{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"risk":0.6555,"urls":["https://linux.oracle.com/cve/CVE-2026-34180.html","https://linux.oracle.com/cve/CVE-2026-34181.html","https://linux.oracle.com/cve/CVE-2026-34182.html","https://linux.oracle.com/cve/CVE-2026-34183.html","https://linux.oracle.com/cve/CVE-2026-42764.html","https://linux.oracle.com/cve/CVE-2026-42766.html","https://linux.oracle.com/cve/CVE-2026-42767.html","https://linux.oracle.com/cve/CVE-2026-42768.html","https://linux.oracle.com/cve/CVE-2026-42769.html","https://linux.oracle.com/cve/CVE-2026-42770.html","https://linux.oracle.com/cve/CVE-2026-45445.html","https://linux.oracle.com/cve/CVE-2026-45446.html","https://linux.oracle.com/cve/CVE-2026-45447.html","https://linux.oracle.com/cve/CVE-2026-7383.html","https://linux.oracle.com/cve/CVE-2026-9076.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-50379.html","description":"[3.5.5-4.0.1_fips]\n- Replace upstream references in fips man pages [Orabug: 35824276]\n- Update additional upstream references\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name [Orabug: 35824276]\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[3.5.5-4.0.1]\n- Replace upstream references [Orabug: 34340177]\n\n[3.5.5.openela.0.1]\n- Add OpenELA specific changes\n\n[1:3.5.5-4]\n- Fix CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-34181,\nCVE-2026-34183, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768,\nCVE-2026-42769, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447,\nCVE-2026-34182.\nResolves:             RHEL-179274\nResolves:             RHEL-179287\nResolves:             RHEL-179539\nResolves:             RHEL-179544\nResolves:             RHEL-179547\nResolves:             RHEL-179552\nResolves:             RHEL-179556\nResolves:             RHEL-179633\nResolves:             RHEL-179661\nResolves:             RHEL-179678\nResolves:             RHEL-179684\nResolves:             RHEL-179688\nResolves:             RHEL-179691\nResolves:             RHEL-179696\nResolves:             RHEL-179699"},"relatedVulnerabilities":[{"id":"CVE-2026-34180","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792}],"urls":["https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d","https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83","https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff","https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43","https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34180","description":"Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-34181","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34181","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34181","date":"2026-10-08","epss":0.00182,"percentile":0.07141}],"urls":["https://github.com/openssl/openssl/commit/0300eb9ddce7a0895bf301a4b0c03a9da2313a0f","https://github.com/openssl/openssl/commit/79eb76a937e474bb7610a0a3dc57131dc8dc6610","https://github.com/openssl/openssl/commit/85dcbb3abaa4878af5c8fbbe11bce708fcf984a7","https://github.com/openssl/openssl/commit/ec36f2417c4ddd8cabce4b4a60a3d7a7365f2d81","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34181","description":"Issue Summary: The PKCS#12 file processing fails to perform sufficient input\nvalidation for files that use Password-Based Message Authentication Code 1\n(PBMAC1) integrity mechanism allowing a certificate and private key forgery.\n\nImpact Summary: An attacker impersonating a user can cause a service reading\nPKCS#12 files to accept forged certificates and private keys with a 1 in 256\nprobability.\n\nIf a service accepting PKCS#12 files is using passwords for authenticating\nthe received files, the attacker can create unencrypted PKCS#12 files that\nuse PBMAC1 authentication that specifies an HMAC key of only one byte, allowing\nthem to craft a file that will be accepted with a 1 in 256 probability.\nThat would then cause the service to accept a certificate and private key\ncontrolled by the attacker.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-34182","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34182","date":"2026-10-08","epss":0.01057,"percentile":0.63405}],"urls":["https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc","https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f","https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7","https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac","https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34182","description":"Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue."},{"id":"CVE-2026-34183","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34183","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34183","date":"2026-10-08","epss":0.01049,"percentile":0.63201}],"urls":["https://github.com/openssl/openssl/commit/5b306efb0b3779dfdd0803b4afc9d08c91f11517","https://github.com/openssl/openssl/commit/7d06955ebe0ecf8adfd4c1e92018586da47ef9ac","https://github.com/openssl/openssl/commit/d2e9efbe4900a373227deb136e8665401404ffac","https://github.com/openssl/openssl/commit/fbaa83859c01ad64f497b757aaf51be7d05ed9eb","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34183","description":"Issue summary: Remote peer may exhaust heap memory of the QUIC\nserver or client by flooding it with packets containing PATH_CHALLENGE\nframes.\n\nImpact summary: A malicious remote peer can cause an unbounded\nmemory allocation which can lead to an abnormal termination of the\napplication acting as a QUIC client or server and a Denial of Service.\n\nA remote peer may exhaust heap memory by flooding the local\nQUIC stack with PATH_CHALLENGE frames. The local QUIC stack\nallocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.\nThe allocated PATH_RESPONSE frame gets freed only when the remote\npeer acknowledges reception of the PATH_RESPONSE frame which will\nnot be done by a malicious peer.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by\nthis issue. The QUIC stack is outside of OpenSSL FIPS module\nboundary."},{"id":"CVE-2026-42764","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42764","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42764","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729","https://github.com/openssl/openssl/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677","https://github.com/openssl/openssl/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42764","description":"Issue summary: Receiving a QUIC initial packet with an invalid token may\ntrigger a NULL pointer dereference in the OpenSSL QUIC server with\naddress validation disabled.\n\nImpact summary: NULL pointer dereference typically causes abnormal termination\nof the affected QUIC server process and a Denial of Service.\n\nIf the address validation is disabled in the OpenSSL QUIC server\nimplementation, an attacker can crash the server by sending an initial\npacket with an invalid or expired token.\n\nBy default, the client address validation is enabled in the OpenSSL QUIC server\nimplementation, which makes the default configuration not vulnerable\nto this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with\nthe SSL_new_listener() call, the address validation is disabled making the\nvulnerable code reachable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42766","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898}],"urls":["https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce","https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4","https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7","https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4","https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42766","description":"Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42767","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42768","cwe":"CWE-514","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42768","date":"2026-10-08","epss":0.00295,"percentile":0.20305}],"urls":["https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f","https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d","https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd","https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42768","description":"Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries — the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42769","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42769","cwe":"CWE-295","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42769","date":"2026-10-08","epss":0.00239,"percentile":0.13688}],"urls":["https://github.com/openssl/openssl/commit/54d0989997e5fc26057009a9782c3441ce3842fb","https://github.com/openssl/openssl/commit/777b363b16fcf2153bb3ded39dc3838713667c44","https://github.com/openssl/openssl/commit/d35cd473a271bf3ce7bf3d32af53217fb83ae92c","https://github.com/openssl/openssl/commit/d531f21c0fe99067a66fc0ff1161ef127f9cd70b","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42769","description":"Issue Summary: An error in the callback used to verify the certificate\nprovided in a Root CA key update Certificate Management Protocol (CMP)\nmessage response rendered the certificate validation ineffectual, which\ncould lead to escalation of credentials from the Registration Authority (RA)\nlevel to the root Certification Authority (root CA) level.\n\nImpact Summary: The Registration Autority could replace the root CA\ncertificate for the CMP clients with an arbitrary root CA certificate.\n\nOne of the parts of the Certificate Management Protocol (CMP), specified in\nRFC 9810, is Root Certification Authority (root CA) key Rollover,\nwhich is sent by the server in a message with type 'id-it-rootCaKeyUpdate'.\nAs part of these messages, 'newWithOld' certificate, the new root CA\ncertificate signed with the old root CA key, is provided, and verifying its\nsignature is crucial for transferring the trust from the old CA key to the\nnew one.\n\nThe 'id-it-rootCaKeyUpdate' messages are expected to be processed with\nOSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld'\ncertificate.  A typo in the certificate chain building code led to adding\nan incorrect certificate ('newWithOld' instead of 'oldRoot') to the\ncertificate chain, rendering the certificate verification process ineffectual\n(only the issuer name and the algorithm OIDs were verified by other parts\nof the verification code).\n\nAn attacker who already has credentials that satisfy the CMP message\nprotection checks can generate a new key pair and use a crafted self-signed\ncertificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP\nclients would accept as a new trust anchor.\n\nSignificant preconditions for the attack (having valid RA-level credentials)\nare the reason the issue was assigned Low severity.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42770","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42770","date":"2026-10-08","epss":0.00258,"percentile":0.16004}],"urls":["https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02","https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb","https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c","https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2","https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42770","description":"Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue."},{"id":"CVE-2026-45445","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45445","date":"2026-10-08","epss":0.00704,"percentile":0.51865}],"urls":["https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451","https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7","https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af","https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c","https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45445","description":"Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-45446","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45446","date":"2026-10-08","epss":0.00236,"percentile":0.13414}],"urls":["https://github.com/openssl/openssl/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc","https://github.com/openssl/openssl/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3","https://github.com/openssl/openssl/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85","https://github.com/openssl/openssl/commit/daca0f48e4a69a2892a62262bad59e62a8a76598","https://github.com/openssl/openssl/commit/eec5e9bf0d867333b8495e456f5235d225798a68","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45446","description":"Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\n\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\n\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only\nif the tag is verified succesfully.\n\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds its\nall-zeros value.\n\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do not\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\n\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\n\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip the\nciphertext update when a message with an empty ciphertext arrives.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-7383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746}],"urls":["https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6","https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74","https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974","https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083","https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7383","description":"Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary."},{"id":"CVE-2026-9076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"urls":["https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb","https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0","https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98","https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26","https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9076","description":"Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue."}]},{"artifact":{"id":"dfd591701b2bf27b","cpes":["cpe:2.3:a:oracleamerica:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:oracleamerica:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/ol/openssl-libs@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.0.1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.5.5-4.0.1.el9_8_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-50379","versionConstraint":"< 10:3.5.5-4.0.1.el9_8_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl-libs","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-50379","fix":{"state":"fixed","versions":["10:3.5.5-4.0.1.el9_8_fips"],"available":[{"date":"2026-07-07","kind":"advisory","version":"10:3.5.5-4.0.1.el9_8_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-34181","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-34183","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42764","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42768","cwe":"CWE-514","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42769","cwe":"CWE-295","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792},{"cve":"CVE-2026-34181","date":"2026-10-08","epss":0.00182,"percentile":0.07141},{"cve":"CVE-2026-34182","date":"2026-10-08","epss":0.01057,"percentile":0.63405},{"cve":"CVE-2026-34183","date":"2026-10-08","epss":0.01049,"percentile":0.63201},{"cve":"CVE-2026-42764","date":"2026-10-08","epss":0.00778,"percentile":0.5448},{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898},{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852},{"cve":"CVE-2026-42768","date":"2026-10-08","epss":0.00295,"percentile":0.20305},{"cve":"CVE-2026-42769","date":"2026-10-08","epss":0.00239,"percentile":0.13688},{"cve":"CVE-2026-42770","date":"2026-10-08","epss":0.00258,"percentile":0.16004},{"cve":"CVE-2026-45445","date":"2026-10-08","epss":0.00704,"percentile":0.51865},{"cve":"CVE-2026-45446","date":"2026-10-08","epss":0.00236,"percentile":0.13414},{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276},{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746},{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"risk":0.6555,"urls":["https://linux.oracle.com/cve/CVE-2026-34180.html","https://linux.oracle.com/cve/CVE-2026-34181.html","https://linux.oracle.com/cve/CVE-2026-34182.html","https://linux.oracle.com/cve/CVE-2026-34183.html","https://linux.oracle.com/cve/CVE-2026-42764.html","https://linux.oracle.com/cve/CVE-2026-42766.html","https://linux.oracle.com/cve/CVE-2026-42767.html","https://linux.oracle.com/cve/CVE-2026-42768.html","https://linux.oracle.com/cve/CVE-2026-42769.html","https://linux.oracle.com/cve/CVE-2026-42770.html","https://linux.oracle.com/cve/CVE-2026-45445.html","https://linux.oracle.com/cve/CVE-2026-45446.html","https://linux.oracle.com/cve/CVE-2026-45447.html","https://linux.oracle.com/cve/CVE-2026-7383.html","https://linux.oracle.com/cve/CVE-2026-9076.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-50379.html","description":"[3.5.5-4.0.1_fips]\n- Replace upstream references in fips man pages [Orabug: 35824276]\n- Update additional upstream references\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name [Orabug: 35824276]\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[3.5.5-4.0.1]\n- Replace upstream references [Orabug: 34340177]\n\n[3.5.5.openela.0.1]\n- Add OpenELA specific changes\n\n[1:3.5.5-4]\n- Fix CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-34181,\nCVE-2026-34183, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768,\nCVE-2026-42769, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447,\nCVE-2026-34182.\nResolves:             RHEL-179274\nResolves:             RHEL-179287\nResolves:             RHEL-179539\nResolves:             RHEL-179544\nResolves:             RHEL-179547\nResolves:             RHEL-179552\nResolves:             RHEL-179556\nResolves:             RHEL-179633\nResolves:             RHEL-179661\nResolves:             RHEL-179678\nResolves:             RHEL-179684\nResolves:             RHEL-179688\nResolves:             RHEL-179691\nResolves:             RHEL-179696\nResolves:             RHEL-179699"},"relatedVulnerabilities":[{"id":"CVE-2026-34180","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792}],"urls":["https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d","https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83","https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff","https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43","https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34180","description":"Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-34181","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34181","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34181","date":"2026-10-08","epss":0.00182,"percentile":0.07141}],"urls":["https://github.com/openssl/openssl/commit/0300eb9ddce7a0895bf301a4b0c03a9da2313a0f","https://github.com/openssl/openssl/commit/79eb76a937e474bb7610a0a3dc57131dc8dc6610","https://github.com/openssl/openssl/commit/85dcbb3abaa4878af5c8fbbe11bce708fcf984a7","https://github.com/openssl/openssl/commit/ec36f2417c4ddd8cabce4b4a60a3d7a7365f2d81","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34181","description":"Issue Summary: The PKCS#12 file processing fails to perform sufficient input\nvalidation for files that use Password-Based Message Authentication Code 1\n(PBMAC1) integrity mechanism allowing a certificate and private key forgery.\n\nImpact Summary: An attacker impersonating a user can cause a service reading\nPKCS#12 files to accept forged certificates and private keys with a 1 in 256\nprobability.\n\nIf a service accepting PKCS#12 files is using passwords for authenticating\nthe received files, the attacker can create unencrypted PKCS#12 files that\nuse PBMAC1 authentication that specifies an HMAC key of only one byte, allowing\nthem to craft a file that will be accepted with a 1 in 256 probability.\nThat would then cause the service to accept a certificate and private key\ncontrolled by the attacker.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-34182","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34182","date":"2026-10-08","epss":0.01057,"percentile":0.63405}],"urls":["https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc","https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f","https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7","https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac","https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34182","description":"Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue."},{"id":"CVE-2026-34183","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34183","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34183","date":"2026-10-08","epss":0.01049,"percentile":0.63201}],"urls":["https://github.com/openssl/openssl/commit/5b306efb0b3779dfdd0803b4afc9d08c91f11517","https://github.com/openssl/openssl/commit/7d06955ebe0ecf8adfd4c1e92018586da47ef9ac","https://github.com/openssl/openssl/commit/d2e9efbe4900a373227deb136e8665401404ffac","https://github.com/openssl/openssl/commit/fbaa83859c01ad64f497b757aaf51be7d05ed9eb","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34183","description":"Issue summary: Remote peer may exhaust heap memory of the QUIC\nserver or client by flooding it with packets containing PATH_CHALLENGE\nframes.\n\nImpact summary: A malicious remote peer can cause an unbounded\nmemory allocation which can lead to an abnormal termination of the\napplication acting as a QUIC client or server and a Denial of Service.\n\nA remote peer may exhaust heap memory by flooding the local\nQUIC stack with PATH_CHALLENGE frames. The local QUIC stack\nallocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.\nThe allocated PATH_RESPONSE frame gets freed only when the remote\npeer acknowledges reception of the PATH_RESPONSE frame which will\nnot be done by a malicious peer.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by\nthis issue. The QUIC stack is outside of OpenSSL FIPS module\nboundary."},{"id":"CVE-2026-42764","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42764","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42764","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729","https://github.com/openssl/openssl/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677","https://github.com/openssl/openssl/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42764","description":"Issue summary: Receiving a QUIC initial packet with an invalid token may\ntrigger a NULL pointer dereference in the OpenSSL QUIC server with\naddress validation disabled.\n\nImpact summary: NULL pointer dereference typically causes abnormal termination\nof the affected QUIC server process and a Denial of Service.\n\nIf the address validation is disabled in the OpenSSL QUIC server\nimplementation, an attacker can crash the server by sending an initial\npacket with an invalid or expired token.\n\nBy default, the client address validation is enabled in the OpenSSL QUIC server\nimplementation, which makes the default configuration not vulnerable\nto this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with\nthe SSL_new_listener() call, the address validation is disabled making the\nvulnerable code reachable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42766","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898}],"urls":["https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce","https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4","https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7","https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4","https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42766","description":"Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42767","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42768","cwe":"CWE-514","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42768","date":"2026-10-08","epss":0.00295,"percentile":0.20305}],"urls":["https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f","https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d","https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd","https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42768","description":"Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries — the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42769","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42769","cwe":"CWE-295","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42769","date":"2026-10-08","epss":0.00239,"percentile":0.13688}],"urls":["https://github.com/openssl/openssl/commit/54d0989997e5fc26057009a9782c3441ce3842fb","https://github.com/openssl/openssl/commit/777b363b16fcf2153bb3ded39dc3838713667c44","https://github.com/openssl/openssl/commit/d35cd473a271bf3ce7bf3d32af53217fb83ae92c","https://github.com/openssl/openssl/commit/d531f21c0fe99067a66fc0ff1161ef127f9cd70b","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42769","description":"Issue Summary: An error in the callback used to verify the certificate\nprovided in a Root CA key update Certificate Management Protocol (CMP)\nmessage response rendered the certificate validation ineffectual, which\ncould lead to escalation of credentials from the Registration Authority (RA)\nlevel to the root Certification Authority (root CA) level.\n\nImpact Summary: The Registration Autority could replace the root CA\ncertificate for the CMP clients with an arbitrary root CA certificate.\n\nOne of the parts of the Certificate Management Protocol (CMP), specified in\nRFC 9810, is Root Certification Authority (root CA) key Rollover,\nwhich is sent by the server in a message with type 'id-it-rootCaKeyUpdate'.\nAs part of these messages, 'newWithOld' certificate, the new root CA\ncertificate signed with the old root CA key, is provided, and verifying its\nsignature is crucial for transferring the trust from the old CA key to the\nnew one.\n\nThe 'id-it-rootCaKeyUpdate' messages are expected to be processed with\nOSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld'\ncertificate.  A typo in the certificate chain building code led to adding\nan incorrect certificate ('newWithOld' instead of 'oldRoot') to the\ncertificate chain, rendering the certificate verification process ineffectual\n(only the issuer name and the algorithm OIDs were verified by other parts\nof the verification code).\n\nAn attacker who already has credentials that satisfy the CMP message\nprotection checks can generate a new key pair and use a crafted self-signed\ncertificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP\nclients would accept as a new trust anchor.\n\nSignificant preconditions for the attack (having valid RA-level credentials)\nare the reason the issue was assigned Low severity.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-42770","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42770","date":"2026-10-08","epss":0.00258,"percentile":0.16004}],"urls":["https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02","https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb","https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c","https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2","https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42770","description":"Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue."},{"id":"CVE-2026-45445","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45445","date":"2026-10-08","epss":0.00704,"percentile":0.51865}],"urls":["https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451","https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7","https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af","https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c","https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45445","description":"Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-45446","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45446","date":"2026-10-08","epss":0.00236,"percentile":0.13414}],"urls":["https://github.com/openssl/openssl/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc","https://github.com/openssl/openssl/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3","https://github.com/openssl/openssl/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85","https://github.com/openssl/openssl/commit/daca0f48e4a69a2892a62262bad59e62a8a76598","https://github.com/openssl/openssl/commit/eec5e9bf0d867333b8495e456f5235d225798a68","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45446","description":"Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\n\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\n\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only\nif the tag is verified succesfully.\n\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds its\nall-zeros value.\n\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do not\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\n\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\n\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip the\nciphertext update when a message with an empty ciphertext arrives.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},{"id":"CVE-2026-7383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746}],"urls":["https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6","https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74","https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974","https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083","https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7383","description":"Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary."},{"id":"CVE-2026-9076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"urls":["https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb","https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0","https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98","https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26","https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9076","description":"Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4601","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4601","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"risk":0.6255000000000001,"urls":["https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/752180","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-25679","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"urls":["https://go.dev/cl/752180","https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4601","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10125","https://access.redhat.com/errata/RHSA-2026:10133","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10158","https://access.redhat.com/errata/RHSA-2026:10169","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:10701","https://access.redhat.com/errata/RHSA-2026:10712","https://access.redhat.com/errata/RHSA-2026:10929","https://access.redhat.com/errata/RHSA-2026:11217","https://access.redhat.com/errata/RHSA-2026:11375","https://access.redhat.com/errata/RHSA-2026:11412","https://access.redhat.com/errata/RHSA-2026:11413","https://access.redhat.com/errata/RHSA-2026:11686","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:11800","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13642","https://access.redhat.com/errata/RHSA-2026:13643","https://access.redhat.com/errata/RHSA-2026:13671","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:19017","https://access.redhat.com/errata/RHSA-2026:19022","https://access.redhat.com/errata/RHSA-2026:19026","https://access.redhat.com/errata/RHSA-2026:19027","https://access.redhat.com/errata/RHSA-2026:19031","https://access.redhat.com/errata/RHSA-2026:19032","https://access.redhat.com/errata/RHSA-2026:19049","https://access.redhat.com/errata/RHSA-2026:19055","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19128","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19181","https://access.redhat.com/errata/RHSA-2026:19184","https://access.redhat.com/errata/RHSA-2026:19185","https://access.redhat.com/errata/RHSA-2026:19207","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19475","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:20088","https://access.redhat.com/errata/RHSA-2026:20581","https://access.redhat.com/errata/RHSA-2026:20582","https://access.redhat.com/errata/RHSA-2026:20584","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:21696","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22733","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24386","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:25043","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26445","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28893","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52389","https://access.redhat.com/errata/RHSA-2026:52390","https://access.redhat.com/errata/RHSA-2026:52391","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:5941","https://access.redhat.com/errata/RHSA-2026:5942","https://access.redhat.com/errata/RHSA-2026:5943","https://access.redhat.com/errata/RHSA-2026:5944","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:6341","https://access.redhat.com/errata/RHSA-2026:6344","https://access.redhat.com/errata/RHSA-2026:6382","https://access.redhat.com/errata/RHSA-2026:6383","https://access.redhat.com/errata/RHSA-2026:6388","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:6720","https://access.redhat.com/errata/RHSA-2026:6802","https://access.redhat.com/errata/RHSA-2026:6949","https://access.redhat.com/errata/RHSA-2026:7005","https://access.redhat.com/errata/RHSA-2026:7009","https://access.redhat.com/errata/RHSA-2026:7011","https://access.redhat.com/errata/RHSA-2026:7259","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7315","https://access.redhat.com/errata/RHSA-2026:7328","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7665","https://access.redhat.com/errata/RHSA-2026:7669","https://access.redhat.com/errata/RHSA-2026:7674","https://access.redhat.com/errata/RHSA-2026:7833","https://access.redhat.com/errata/RHSA-2026:7834","https://access.redhat.com/errata/RHSA-2026:7876","https://access.redhat.com/errata/RHSA-2026:7877","https://access.redhat.com/errata/RHSA-2026:7878","https://access.redhat.com/errata/RHSA-2026:7879","https://access.redhat.com/errata/RHSA-2026:7883","https://access.redhat.com/errata/RHSA-2026:7992","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8314","https://access.redhat.com/errata/RHSA-2026:8322","https://access.redhat.com/errata/RHSA-2026:8324","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8434","https://access.redhat.com/errata/RHSA-2026:8456","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:8484","https://access.redhat.com/errata/RHSA-2026:8490","https://access.redhat.com/errata/RHSA-2026:8491","https://access.redhat.com/errata/RHSA-2026:8493","https://access.redhat.com/errata/RHSA-2026:8840","https://access.redhat.com/errata/RHSA-2026:8841","https://access.redhat.com/errata/RHSA-2026:8842","https://access.redhat.com/errata/RHSA-2026:8845","https://access.redhat.com/errata/RHSA-2026:8847","https://access.redhat.com/errata/RHSA-2026:8848","https://access.redhat.com/errata/RHSA-2026:8849","https://access.redhat.com/errata/RHSA-2026:8851","https://access.redhat.com/errata/RHSA-2026:8852","https://access.redhat.com/errata/RHSA-2026:8853","https://access.redhat.com/errata/RHSA-2026:8855","https://access.redhat.com/errata/RHSA-2026:8856","https://access.redhat.com/errata/RHSA-2026:8860","https://access.redhat.com/errata/RHSA-2026:8877","https://access.redhat.com/errata/RHSA-2026:8878","https://access.redhat.com/errata/RHSA-2026:8879","https://access.redhat.com/errata/RHSA-2026:8881","https://access.redhat.com/errata/RHSA-2026:8882","https://access.redhat.com/errata/RHSA-2026:8930","https://access.redhat.com/errata/RHSA-2026:8931","https://access.redhat.com/errata/RHSA-2026:8949","https://access.redhat.com/errata/RHSA-2026:9043","https://access.redhat.com/errata/RHSA-2026:9044","https://access.redhat.com/errata/RHSA-2026:9052","https://access.redhat.com/errata/RHSA-2026:9090","https://access.redhat.com/errata/RHSA-2026:9093","https://access.redhat.com/errata/RHSA-2026:9094","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/errata/RHSA-2026:9434","https://access.redhat.com/errata/RHSA-2026:9435","https://access.redhat.com/errata/RHSA-2026:9436","https://access.redhat.com/errata/RHSA-2026:9439","https://access.redhat.com/errata/RHSA-2026:9440","https://access.redhat.com/errata/RHSA-2026:9448","https://access.redhat.com/errata/RHSA-2026:9453","https://access.redhat.com/errata/RHSA-2026:9461","https://access.redhat.com/errata/RHSA-2026:9695","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/errata/RHSA-2026:9872","https://access.redhat.com/security/cve/CVE-2026-25679","https://bugzilla.redhat.com/show_bug.cgi?id=2445356","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25679","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4981","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4981","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"risk":0.60975,"urls":["https://go.dev/cl/767860","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78803","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."},"relatedVulnerabilities":[{"id":"CVE-2026-33811","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"urls":["https://go.dev/cl/767860","https://go.dev/issue/78803","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4981","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:35995","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36617","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36776","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:39266","https://access.redhat.com/errata/RHSA-2026:39272","https://access.redhat.com/errata/RHSA-2026:39319","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54556","https://access.redhat.com/errata/RHSA-2026:54584","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56790","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60302","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61313","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/security/cve/CVE-2026-33811","https://bugzilla.redhat.com/show_bug.cgi?id=2467822","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33811","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4977","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4977","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"risk":0.5984999999999999,"urls":["https://go.dev/cl/771520","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78987","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."},"relatedVulnerabilities":[{"id":"CVE-2026-42499","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"urls":["https://go.dev/cl/771520","https://go.dev/issue/78987","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4977","https://access.redhat.com/errata/RHSA-2026:17713","https://access.redhat.com/errata/RHSA-2026:17714","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:63163","https://access.redhat.com/errata/RHSA-2026:63332","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:64818","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67148","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-42499","https://bugzilla.redhat.com/show_bug.cgi?id=2467809","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42499","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4986","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4986","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"risk":0.588,"urls":["https://go.dev/cl/759940","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78566","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-39820","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"urls":["https://go.dev/cl/759940","https://go.dev/issue/78566","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4986","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54883","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57401","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-39820","https://bugzilla.redhat.com/show_bug.cgi?id=2467820","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39820","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4009","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4009","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61723","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61723","date":"2026-10-08","epss":0.00661,"percentile":0.50098}],"risk":0.49575,"urls":["https://go.dev/cl/709858","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75676","description":"The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input.\n\nThis affects programs which parse untrusted PEM inputs."},"relatedVulnerabilities":[{"id":"CVE-2025-61723","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61723","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61723","date":"2026-10-08","epss":0.00661,"percentile":0.50098}],"urls":["https://go.dev/cl/709858","https://go.dev/issue/75676","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4009","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61723","description":"The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4006","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4006","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61725","date":"2026-10-08","epss":0.00647,"percentile":0.49441}],"risk":0.48525,"urls":["https://go.dev/issue/75680","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709860","description":"The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61725","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61725","date":"2026-10-08","epss":0.00647,"percentile":0.49441}],"urls":["https://go.dev/cl/709860","https://go.dev/issue/75680","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4006","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61725","description":"The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4870","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4870","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"risk":0.46575,"urls":["https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763767","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.\n\nThis only affects TLS 1.3."},"relatedVulnerabilities":[{"id":"CVE-2026-32283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"urls":["https://go.dev/cl/763767","https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4870","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11704","https://access.redhat.com/errata/RHSA-2026:11711","https://access.redhat.com/errata/RHSA-2026:11712","https://access.redhat.com/errata/RHSA-2026:11863","https://access.redhat.com/errata/RHSA-2026:11881","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17075","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19134","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19136","https://access.redhat.com/errata/RHSA-2026:19137","https://access.redhat.com/errata/RHSA-2026:19139","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19156","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19351","https://access.redhat.com/errata/RHSA-2026:19352","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19369","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55898","https://access.redhat.com/errata/RHSA-2026:55900","https://access.redhat.com/errata/RHSA-2026:55901","https://access.redhat.com/errata/RHSA-2026:55902","https://access.redhat.com/errata/RHSA-2026:55903","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:57802","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65343","https://access.redhat.com/errata/RHSA-2026:65514","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66084","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:66523","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/security/cve/CVE-2026-32283","https://bugzilla.redhat.com/show_bug.cgi?id=2456338","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32283","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4971","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4971","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"risk":0.46499999999999997,"urls":["https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://go.dev/cl/775320"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79006","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."},"relatedVulnerabilities":[{"id":"CVE-2026-39836","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"urls":["https://go.dev/cl/775320","https://go.dev/issue/79006","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4971"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39836","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4947","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4947","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"risk":0.46125000000000005,"urls":["https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758320","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."},"relatedVulnerabilities":[{"id":"CVE-2026-32280","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"urls":["https://go.dev/cl/758320","https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4947","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16476","https://access.redhat.com/errata/RHSA-2026:16477","https://access.redhat.com/errata/RHSA-2026:16505","https://access.redhat.com/errata/RHSA-2026:16508","https://access.redhat.com/errata/RHSA-2026:16532","https://access.redhat.com/errata/RHSA-2026:16534","https://access.redhat.com/errata/RHSA-2026:16535","https://access.redhat.com/errata/RHSA-2026:16537","https://access.redhat.com/errata/RHSA-2026:16542","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21338","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:22130","https://access.redhat.com/errata/RHSA-2026:22141","https://access.redhat.com/errata/RHSA-2026:22258","https://access.redhat.com/errata/RHSA-2026:22260","https://access.redhat.com/errata/RHSA-2026:22268","https://access.redhat.com/errata/RHSA-2026:22309","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22415","https://access.redhat.com/errata/RHSA-2026:22422","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22840","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22958","https://access.redhat.com/errata/RHSA-2026:22959","https://access.redhat.com/errata/RHSA-2026:22960","https://access.redhat.com/errata/RHSA-2026:22961","https://access.redhat.com/errata/RHSA-2026:22962","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23244","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24359","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24478","https://access.redhat.com/errata/RHSA-2026:24716","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:28196","https://access.redhat.com/errata/RHSA-2026:28198","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:39894","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49526","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49838","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:59834","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61685","https://access.redhat.com/errata/RHSA-2026:61906","https://access.redhat.com/errata/RHSA-2026:61907","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/security/cve/CVE-2026-32280","https://bugzilla.redhat.com/show_bug.cgi?id=2456339","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32280","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5037","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5037","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"risk":0.4432500000000001,"urls":["https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/783621","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname.\n\nWith a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."},"relatedVulnerabilities":[{"id":"CVE-2026-27145","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"urls":["https://go.dev/cl/783621","https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5037","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:29980","https://access.redhat.com/errata/RHSA-2026:29981","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46394","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49705","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:49729","https://access.redhat.com/errata/RHSA-2026:49744","https://access.redhat.com/errata/RHSA-2026:49765","https://access.redhat.com/errata/RHSA-2026:49770","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:52946","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53416","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54427","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55899","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59556","https://access.redhat.com/errata/RHSA-2026:59557","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60386","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60388","https://access.redhat.com/errata/RHSA-2026:60390","https://access.redhat.com/errata/RHSA-2026:60391","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:63016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68335","https://access.redhat.com/security/cve/CVE-2026-27145","https://bugzilla.redhat.com/show_bug.cgi?id=2484207","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27145","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4342","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4342","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"risk":0.430675,"urls":["https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736713","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."},"relatedVulnerabilities":[{"id":"CVE-2025-61728","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"urls":["https://go.dev/cl/736713","https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4342","http://www.openwall.com/lists/oss-security/2026/01/15/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61728","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5038","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5038","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"risk":0.42,"urls":["https://go.dev/cl/774481","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79217","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-42504","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"urls":["https://go.dev/cl/774481","https://go.dev/issue/79217","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5038"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42504","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."}]},{"artifact":{"id":"cf3f4f305e651dab","cpes":["cpe:2.3:a:oracleamerica:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/ol/openssl@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.5.5-3.0.1.el9_8_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-50345","versionConstraint":"< 10:3.5.5-3.0.1.el9_8_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-50345","fix":{"state":"fixed","versions":["10:3.5.5-3.0.1.el9_8_fips"],"available":[{"date":"2026-06-24","kind":"advisory","version":"10:3.5.5-3.0.1.el9_8_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"risk":0.40249999999999997,"urls":["https://linux.oracle.com/cve/CVE-2026-28390.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-50345.html","description":"[3.5.5-3.0.1]\n- Replace upstream references in fips man pages [Orabug: 35824276]\n- Update additional upstream references\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name [Orabug: 35824276]\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[1:3.5.5-3]\n- Fix CVE-2026-28390\n  Resolves: RHEL-165870\n\n[1:3.5.5-2]\n- Fix CVE-2026-31790\n  Resolves: RHEL-161586\n\n[1:3.5.5-1]\n- Rebase to OpenSSL 3.5.5\n  Resolves: RHEL-136895\n  Resolves: RHEL-142004\n  Resolves: RHEL-142012\n  Resolves: RHEL-142020\n  Resolves: RHEL-142024\n  Resolves: RHEL-142028\n  Resolves: RHEL-142032\n  Resolves: RHEL-142036\n  Resolves: RHEL-142040\n  Resolves: RHEL-142044\n  Resolves: RHEL-142048\n  Resolves: RHEL-142052\n  Resolves: RHEL-142056"},"relatedVulnerabilities":[{"id":"CVE-2026-28390","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"urls":["https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc","https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6","https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4","https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788","https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28390","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"dfd591701b2bf27b","cpes":["cpe:2.3:a:oracleamerica:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:oracleamerica:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.0.1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/ol/openssl-libs@3.5.8-1.0.1.el9_8?arch=x86_64&distro=ol-9.8&epoch=1&upstream=openssl-3.5.8-1.0.1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.0.1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.0.1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.5.5-3.0.1.el9_8_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-50345","versionConstraint":"< 10:3.5.5-3.0.1.el9_8_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"openssl-libs","version":"1:3.5.8-1.0.1.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-50345","fix":{"state":"fixed","versions":["10:3.5.5-3.0.1.el9_8_fips"],"available":[{"date":"2026-06-24","kind":"advisory","version":"10:3.5.5-3.0.1.el9_8_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"risk":0.40249999999999997,"urls":["https://linux.oracle.com/cve/CVE-2026-28390.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-50345.html","description":"[3.5.5-3.0.1]\n- Replace upstream references in fips man pages [Orabug: 35824276]\n- Update additional upstream references\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35824276]\n- Update FIPS module name [Orabug: 35824276]\n- Enable openssl-fips-provider dependency [Orabug: 36504822]\n- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]\n- Replace upstream references [Orabug: 34340177]\n\n[1:3.5.5-3]\n- Fix CVE-2026-28390\n  Resolves: RHEL-165870\n\n[1:3.5.5-2]\n- Fix CVE-2026-31790\n  Resolves: RHEL-161586\n\n[1:3.5.5-1]\n- Rebase to OpenSSL 3.5.5\n  Resolves: RHEL-136895\n  Resolves: RHEL-142004\n  Resolves: RHEL-142012\n  Resolves: RHEL-142020\n  Resolves: RHEL-142024\n  Resolves: RHEL-142028\n  Resolves: RHEL-142032\n  Resolves: RHEL-142036\n  Resolves: RHEL-142040\n  Resolves: RHEL-142044\n  Resolves: RHEL-142048\n  Resolves: RHEL-142052\n  Resolves: RHEL-142056"},"relatedVulnerabilities":[{"id":"CVE-2026-28390","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"urls":["https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc","https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6","https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4","https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788","https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28390","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f02d56b67963eac2","cpes":["cpe:2.3:a:oracleamerica:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:gnutls:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/ol/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=ol-9.8&upstream=gnutls-3.8.10-8.el9_8.src.rpm","type":"rpm","version":"3.8.10-8.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.8.3-4.el9_4_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2024-12364","versionConstraint":"< 10:3.8.3-4.el9_4_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-8.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2024-12364","fix":{"state":"fixed","versions":["10:3.8.3-4.el9_4_fips"],"available":[{"date":"2024-05-08","kind":"advisory","version":"10:3.8.3-4.el9_4_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2024-28834","cwe":"CWE-327","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-28835","cwe":"CWE-248","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-28834","date":"2026-10-08","epss":0.00724,"percentile":0.52616},{"cve":"CVE-2024-28835","date":"2026-10-08","epss":0.00389,"percentile":0.30895}],"risk":0.362,"urls":["https://linux.oracle.com/cve/CVE-2024-28834.html","https://linux.oracle.com/cve/CVE-2024-28835.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2024-12364.html","description":"[3.8.3-4_fips]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35925409]\n- Update FIPS module name for Oracle Linux [Orabug: 35925409]\n\n[3.8.3-4]\n- Bump release to ensure el9 package is greater than el9_* packages\n\n[3.8.3-3]\n- Bump release to ensure el9 package is greater than el9_* packages\n\n[3.8.3-2]\n- Fix timing side-channel in deterministic ECDSA (RHEL-28959)\n- Fix potential crash during chain building/verification (RHEL-28954)\n\n[3.8.3-1]\n- Update to gnutls 3.8.3 (RHEL-14891)\n\n[3.8.2-3]\n- Skip KTLS test exercising ChaCha20-Poly1305 in TLS 1.3 as well (RHEL-18498)\n\n[3.8.2-2]\n- Bump nettle dependency to 3.9.1\n- Skip KTLS test exercising ChaCha20-Poly1305 in TLS 1.2 (RHEL-18498)\n\n[3.8.2-1]\n- Update to gnutls 3.8.2 (RHEL-14891)"},"relatedVulnerabilities":[{"id":"CVE-2024-28834","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28834","cwe":"CWE-327","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-28834","date":"2026-10-08","epss":0.00724,"percentile":0.52616}],"urls":["https://access.redhat.com/errata/RHSA-2024:1784","https://access.redhat.com/errata/RHSA-2024:1879","https://access.redhat.com/errata/RHSA-2024:1997","https://access.redhat.com/errata/RHSA-2024:2044","https://access.redhat.com/errata/RHSA-2024:2570","https://access.redhat.com/errata/RHSA-2024:2889","https://access.redhat.com/security/cve/CVE-2024-28834","https://bugzilla.redhat.com/show_bug.cgi?id=2269228","https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html","https://minerva.crocs.fi.muni.cz/","http://www.openwall.com/lists/oss-security/2024/03/22/1","http://www.openwall.com/lists/oss-security/2024/03/22/2","https://lists.debian.org/debian-lts-announce/2024/09/msg00019.html","https://people.redhat.com/~hkario/marvin/","https://security.netapp.com/advisory/ntap-20240524-0004/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28834","description":"A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel."},{"id":"CVE-2024-28835","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28835","cwe":"CWE-248","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-28835","date":"2026-10-08","epss":0.00389,"percentile":0.30895}],"urls":["https://access.redhat.com/errata/RHSA-2024:1879","https://access.redhat.com/errata/RHSA-2024:2570","https://access.redhat.com/errata/RHSA-2024:2889","https://access.redhat.com/security/cve/CVE-2024-28835","https://bugzilla.redhat.com/show_bug.cgi?id=2269084","https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html","http://www.openwall.com/lists/oss-security/2024/03/22/1","http://www.openwall.com/lists/oss-security/2024/03/22/2","https://lists.debian.org/debian-lts-announce/2024/09/msg00019.html","https://security.netapp.com/advisory/ntap-20241122-0009/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28835","description":"A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the \"certtool --verify-chain\" command."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4155","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4155","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"risk":0.34275,"urls":["https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/725920","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"urls":["https://go.dev/cl/725920","https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4155"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61729","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."}]},{"artifact":{"id":"f02d56b67963eac2","cpes":["cpe:2.3:a:oracleamerica:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:gnutls:gnutls:3.8.10-8.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/ol/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=ol-9.8&upstream=gnutls-3.8.10-8.el9_8.src.rpm","type":"rpm","version":"3.8.10-8.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:3.8.3-10.el9_7_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-50149","versionConstraint":"< 10:3.8.3-10.el9_7_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-8.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-50149","fix":{"state":"fixed","versions":["10:3.8.3-10.el9_7_fips"],"available":[{"date":"2026-03-12","kind":"advisory","version":"10:3.8.3-10.el9_7_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-14831","cwe":"CWE-407","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2025-9820","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14831","date":"2026-10-08","epss":0.00666,"percentile":0.50289},{"cve":"CVE-2025-9820","date":"2026-10-08","epss":0.00226,"percentile":0.12203}],"risk":0.333,"urls":["https://linux.oracle.com/cve/CVE-2025-14831.html","https://linux.oracle.com/cve/CVE-2025-9820.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-50149.html","description":"[3.8.3-10_fips]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35925409]\n- Update FIPS module name for Oracle Linux [Orabug: 35925409]\n\n[3.8.3-10]\n- Fix PKCS#11 token initialization label overflow (CVE-2025-9820)\n- Fix name constraint processing performance issue (CVE-2025-14831)"},"relatedVulnerabilities":[{"id":"CVE-2025-14831","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14831","cwe":"CWE-407","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14831","date":"2026-10-08","epss":0.00666,"percentile":0.50289}],"urls":["https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:3477","https://access.redhat.com/errata/RHSA-2026:4188","https://access.redhat.com/errata/RHSA-2026:4655","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:5585","https://access.redhat.com/errata/RHSA-2026:5606","https://access.redhat.com/errata/RHSA-2026:6618","https://access.redhat.com/errata/RHSA-2026:6630","https://access.redhat.com/errata/RHSA-2026:6737","https://access.redhat.com/errata/RHSA-2026:6738","https://access.redhat.com/errata/RHSA-2026:7329","https://access.redhat.com/errata/RHSA-2026:7335","https://access.redhat.com/errata/RHSA-2026:7477","https://access.redhat.com/errata/RHSA-2026:8746","https://access.redhat.com/errata/RHSA-2026:8747","https://access.redhat.com/errata/RHSA-2026:8748","https://access.redhat.com/security/cve/CVE-2025-14831","https://bugzilla.redhat.com/show_bug.cgi?id=2423177","https://gitlab.com/gnutls/gnutls/-/issues/1773","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14831","description":"A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs)."},{"id":"CVE-2025-9820","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9820","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-9820","date":"2026-10-08","epss":0.00226,"percentile":0.12203}],"urls":["https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:3477","https://access.redhat.com/errata/RHSA-2026:4188","https://access.redhat.com/errata/RHSA-2026:4655","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:5585","https://access.redhat.com/errata/RHSA-2026:5606","https://access.redhat.com/errata/RHSA-2026:7329","https://access.redhat.com/errata/RHSA-2026:7477","https://access.redhat.com/security/cve/CVE-2025-9820","https://bugzilla.redhat.com/show_bug.cgi?id=2392528","https://gitlab.com/gnutls/gnutls/-/commit/1d56f96f6ab5034d677136b9d50b5a75dff0faf5","https://gitlab.com/gnutls/gnutls/-/issues/1732","https://www.gnutls.org/security-new.html#GNUTLS-SA-2025-11-18","http://www.openwall.com/lists/oss-security/2025/11/20/2","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9820","description":"A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4007","versionConstraint":"<1.24.9||>=1.25.0,<1.25.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4007","fix":{"state":"fixed","versions":["1.24.9","1.25.3"],"available":[{"date":"2025-10-13","kind":"release","version":"1.24.9"},{"date":"2025-10-13","kind":"release","version":"1.25.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58187","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58187","date":"2026-10-08","epss":0.00406,"percentile":0.32778}],"risk":0.3045,"urls":["https://go.dev/cl/709854","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75681","description":"Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate.\n\nThis affects programs which validate arbitrary certificate chains."},"relatedVulnerabilities":[{"id":"CVE-2025-58187","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58187","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58187","date":"2026-10-08","epss":0.00406,"percentile":0.32778}],"urls":["https://go.dev/cl/709854","https://go.dev/issue/75681","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4007","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58187","description":"Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4012","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4012","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58186","date":"2026-10-08","epss":0.00565,"percentile":0.45157}],"risk":0.290975,"urls":["https://go.dev/cl/709855","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75672","description":"Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as \"a=;\", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-58186","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58186","date":"2026-10-08","epss":0.00565,"percentile":0.45157}],"urls":["https://go.dev/cl/709855","https://go.dev/issue/75672","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4012","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58186","description":"Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as \"a=;\", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4011","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4011","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58185","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58185","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"risk":0.28634,"urls":["https://go.dev/cl/709856","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75671","description":"Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2025-58185","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58185","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58185","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"urls":["https://go.dev/cl/709856","https://go.dev/issue/75671","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4011","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58185","description":"Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4015","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4015","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61724","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61724","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"risk":0.28634,"urls":["https://go.dev/issue/75716","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709859","description":"The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61724","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61724","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61724","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"urls":["https://go.dev/cl/709859","https://go.dev/issue/75716","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4015","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61724","description":"The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4013","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4013","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58188","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58188","date":"2026-10-08","epss":0.00381,"percentile":0.30022}],"risk":0.28575,"urls":["https://go.dev/issue/75675","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709853","description":"Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method.\n\nThis affects programs which validate arbitrary certificate chains."},"relatedVulnerabilities":[{"id":"CVE-2025-58188","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58188","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58188","date":"2026-10-08","epss":0.00381,"percentile":0.30022}],"urls":["https://go.dev/cl/709853","https://go.dev/issue/75675","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4013","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58188","description":"Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4946","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4946","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"risk":0.26625,"urls":["https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758061","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.\n\nThis only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."},"relatedVulnerabilities":[{"id":"CVE-2026-32281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"urls":["https://go.dev/cl/758061","https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4946"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32281","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."}]},{"artifact":{"id":"c2c0e7362117fe90","cpes":["cpe:2.3:a:pip_developers_\\<distutils_sig_project:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:pip:25.3:*:*:*:*:*:*:*"],"name":"pip","purl":"pkg:pypi/pip@25.3","type":"python","version":"25.3","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"26.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wf93-45jw-7689","versionConstraint":"<26.1.2 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pip","version":"25.3"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-wf93-45jw-7689","fix":{"state":"fixed","versions":["26.1.2"],"available":[{"date":"2026-07-09","kind":"first-observed","version":"26.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8643","date":"2026-10-08","epss":0.00466,"percentile":0.38331}],"risk":0.257465,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-8643","https://github.com/pypa/pip/pull/14000","https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ","http://www.openwall.com/lists/oss-security/2026/06/01/5","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json","https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-196.yaml","https://bugzilla.redhat.com/show_bug.cgi?id=2460927","https://access.redhat.com/security/cve/CVE-2026-8643","https://access.redhat.com/errata/RHSA-2026:36315","https://access.redhat.com/errata/RHSA-2026:36193","https://access.redhat.com/errata/RHSA-2026:34891","https://access.redhat.com/errata/RHSA-2026:34780","https://access.redhat.com/errata/RHSA-2026:34778","https://access.redhat.com/errata/RHSA-2026:34777","https://access.redhat.com/errata/RHSA-2026:34776","https://access.redhat.com/errata/RHSA-2026:34775","https://access.redhat.com/errata/RHSA-2026:34774","https://access.redhat.com/errata/RHSA-2026:34773","https://access.redhat.com/errata/RHSA-2026:34772","https://access.redhat.com/errata/RHSA-2026:34765","https://access.redhat.com/errata/RHSA-2026:34760","https://access.redhat.com/errata/RHSA-2026:34758","https://access.redhat.com/errata/RHSA-2026:34756","https://access.redhat.com/errata/RHSA-2026:34752","https://access.redhat.com/errata/RHSA-2026:34750","https://access.redhat.com/errata/RHSA-2026:34749","https://access.redhat.com/errata/RHSA-2026:34748","https://access.redhat.com/errata/RHSA-2026:34741","https://access.redhat.com/errata/RHSA-2026:34740","https://access.redhat.com/errata/RHSA-2026:34739","https://access.redhat.com/errata/RHSA-2026:34456","https://access.redhat.com/errata/RHSA-2026:34374","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37283"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wf93-45jw-7689","description":"pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory"},"relatedVulnerabilities":[{"id":"CVE-2026-8643","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8643","date":"2026-10-08","epss":0.00466,"percentile":0.38331}],"urls":["https://github.com/pypa/pip/pull/14000","https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/","http://www.openwall.com/lists/oss-security/2026/06/01/5","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:34374","https://access.redhat.com/errata/RHSA-2026:34456","https://access.redhat.com/errata/RHSA-2026:34739","https://access.redhat.com/errata/RHSA-2026:34740","https://access.redhat.com/errata/RHSA-2026:34741","https://access.redhat.com/errata/RHSA-2026:34748","https://access.redhat.com/errata/RHSA-2026:34749","https://access.redhat.com/errata/RHSA-2026:34750","https://access.redhat.com/errata/RHSA-2026:34752","https://access.redhat.com/errata/RHSA-2026:34756","https://access.redhat.com/errata/RHSA-2026:34758","https://access.redhat.com/errata/RHSA-2026:34760","https://access.redhat.com/errata/RHSA-2026:34765","https://access.redhat.com/errata/RHSA-2026:34772","https://access.redhat.com/errata/RHSA-2026:34773","https://access.redhat.com/errata/RHSA-2026:34774","https://access.redhat.com/errata/RHSA-2026:34775","https://access.redhat.com/errata/RHSA-2026:34776","https://access.redhat.com/errata/RHSA-2026:34777","https://access.redhat.com/errata/RHSA-2026:34778","https://access.redhat.com/errata/RHSA-2026:34780","https://access.redhat.com/errata/RHSA-2026:34891","https://access.redhat.com/errata/RHSA-2026:36193","https://access.redhat.com/errata/RHSA-2026:36315","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37283","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42144","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:50479","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:56347","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/security/cve/CVE-2026-8643","https://bugzilla.redhat.com/show_bug.cgi?id=2460927","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8643","description":"pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4008","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4008","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58189","cwe":"CWE-532","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58189","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"risk":0.24101999999999998,"urls":["https://go.dev/issue/75652","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/707776","description":"When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped."},"relatedVulnerabilities":[{"id":"CVE-2025-58189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58189","cwe":"CWE-532","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58189","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"urls":["https://go.dev/cl/707776","https://go.dev/issue/75652","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4008","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58189","description":"When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4010","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4010","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47912","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"risk":0.24101999999999998,"urls":["https://go.dev/cl/709857","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75678","description":"The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: \"http://[::1]/\". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement."},"relatedVulnerabilities":[{"id":"CVE-2025-47912","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47912","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"urls":["https://go.dev/cl/709857","https://go.dev/issue/75678","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4010","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47912","description":"The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: \"http://[::1]/\". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement."}]},{"artifact":{"id":"6414af6363f31899","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/direct_url.json","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/direct_url.json","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vxq7-64xx-v4gw","versionConstraint":">=1.10.3,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-vxq7-64xx-v4gw","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"risk":0.23944000000000001,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw","https://nvd.nist.gov/vuln/detail/CVE-2026-97689","https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vxq7-64xx-v4gw","description":"urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory"},"relatedVulnerabilities":[{"id":"CVE-2026-97689","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"urls":["https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97689","description":"urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4980","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4980","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"risk":0.21811499999999998,"urls":["https://go.dev/cl/771180","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78981","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."},"relatedVulnerabilities":[{"id":"CVE-2026-39826","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"urls":["https://go.dev/cl/771180","https://go.dev/issue/78981","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4980"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39826","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."}]},{"artifact":{"id":"3f1bb178488b64cc","cpes":["cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@46.0.7","type":"python","version":"46.0.7","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/direct_url.json","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/direct_url.json","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"50.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g6cj-pr64-35w5","versionConstraint":">=44.0.0,<50.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"46.0.7"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-g6cj-pr64-35w5","fix":{"state":"fixed","versions":["50.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"50.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69247","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69247","cwe":"CWE-209","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69247","date":"2026-10-08","epss":0.00274,"percentile":0.18196}],"risk":0.21508999999999995,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5","https://github.com/pyca/cryptography/pull/15369","https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g6cj-pr64-35w5","description":"cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing"},"relatedVulnerabilities":[{"id":"CVE-2026-69247","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69247","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69247","cwe":"CWE-209","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69247","date":"2026-10-08","epss":0.00274,"percentile":0.18196}],"urls":["https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f","https://github.com/pyca/cryptography/pull/15369","https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69247","description":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4976","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4976","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"risk":0.212695,"urls":["https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/770541","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions.\n\nWhen used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function.\n\nFor example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."},"relatedVulnerabilities":[{"id":"CVE-2026-39825","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"urls":["https://go.dev/cl/770541","https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4976"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39825","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5039","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5039","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"risk":0.21218,"urls":["https://go.dev/cl/777060","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79346","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."},"relatedVulnerabilities":[{"id":"CVE-2026-42507","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"urls":["https://go.dev/cl/777060","https://go.dev/issue/79346","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5039"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42507","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4014","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4014","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58183","date":"2026-10-08","epss":0.00443,"percentile":0.36489}],"risk":0.20599499999999996,"urls":["https://go.dev/issue/75677","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709861","description":"tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations."},"relatedVulnerabilities":[{"id":"CVE-2025-58183","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58183","date":"2026-10-08","epss":0.00443,"percentile":0.36489}],"urls":["https://go.dev/cl/709861","https://go.dev/issue/75677","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4014","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58183","description":"tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations."}]},{"artifact":{"id":"3f1bb178488b64cc","cpes":["cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@46.0.7","type":"python","version":"46.0.7","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/direct_url.json","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/direct_url.json","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"49.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jwv3-5hgf-82ww","versionConstraint":">=42.0.0,<49.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"46.0.7"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-jwv3-5hgf-82ww","fix":{"state":"fixed","versions":["49.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"49.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69249","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69249","date":"2026-10-08","epss":0.00252,"percentile":0.15305}],"risk":0.20412,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","https://nvd.nist.gov/vuln/detail/CVE-2026-69249","https://github.com/pyca/cryptography/commit/3763aa79b","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jwv3-5hgf-82ww","description":"python-cryptography: Duplicate self-signed intermediates can cause exponential path-building"},"relatedVulnerabilities":[{"id":"CVE-2026-69249","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69249","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69249","date":"2026-10-08","epss":0.00252,"percentile":0.15305}],"urls":["https://github.com/pyca/cryptography/commit/3763aa79b","https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69249","description":"python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5856","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5856","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"risk":0.19673,"urls":["https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/775960","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."},"relatedVulnerabilities":[{"id":"CVE-2026-42505","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"urls":["https://go.dev/cl/775960","https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-5856"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42505","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4603","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4603","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"risk":0.19202999999999998,"urls":["https://go.dev/issue/77954","https://go.dev/cl/752081"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\".\n\nA new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."},"relatedVulnerabilities":[{"id":"CVE-2026-27142","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"urls":["https://go.dev/cl/752081","https://go.dev/issue/77954","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4603"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27142","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4865","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4865","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763762","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied.\n\nThese issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."},"relatedVulnerabilities":[{"id":"CVE-2026-32289","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/763762","https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4865"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32289","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4982","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4982","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/cl/769920","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78913","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-39823","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/769920","https://go.dev/issue/78913","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4982"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39823","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."}]},{"artifact":{"id":"3f1bb178488b64cc","cpes":["cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@46.0.7","type":"python","version":"46.0.7","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/direct_url.json","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/direct_url.json","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"49.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m2h6-j472-rp4c","versionConstraint":">=45.0.0,<49.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"46.0.7"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-m2h6-j472-rp4c","fix":{"state":"fixed","versions":["49.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"49.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69248","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69248","date":"2026-10-08","epss":0.00309,"percentile":0.21751}],"risk":0.183855,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c","https://github.com/pyca/cryptography/pull/14888","https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2","https://nvd.nist.gov/vuln/detail/CVE-2026-69248","https://github.com/pyca/cryptography/commit/286c89128","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3554.yaml"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m2h6-j472-rp4c","description":"python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees"},"relatedVulnerabilities":[{"id":"CVE-2026-69248","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69248","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69248","date":"2026-10-08","epss":0.00309,"percentile":0.21751}],"urls":["https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2","https://github.com/pyca/cryptography/pull/14888","https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69248","description":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0."}]},{"artifact":{"id":"6414af6363f31899","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/direct_url.json","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/direct_url.json","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8988-9cw3-xx77","versionConstraint":">=1.26.0,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-8988-9cw3-xx77","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"risk":0.18270999999999998,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77","https://nvd.nist.gov/vuln/detail/CVE-2026-97687","https://github.com/urllib3/urllib3/pull/5093","https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465","https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8988-9cw3-xx77","description":"urllib3: HTTPS proxy TLS configuration may be ignored or overridden"},"relatedVulnerabilities":[{"id":"CVE-2026-97687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"urls":["https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465","https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3","https://github.com/urllib3/urllib3/pull/5093","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97687","description":"urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4970","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4970","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"risk":0.17748,"urls":["https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://go.dev/cl/797880"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79005","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /.\n\nFor example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."},"relatedVulnerabilities":[{"id":"CVE-2026-39822","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"urls":["https://go.dev/cl/797880","https://go.dev/issue/79005","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-4970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39822","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."}]},{"artifact":{"id":"6414af6363f31899","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/direct_url.json","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/direct_url.json","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gh4c-6fx4-qh6g","versionConstraint":">=2.6.2,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-gh4c-6fx4-qh6g","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"risk":0.173145,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g","https://nvd.nist.gov/vuln/detail/CVE-2026-97688","https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gh4c-6fx4-qh6g","description":"urllib3: Chunked Deflate streaming can enter an infinite loop"},"relatedVulnerabilities":[{"id":"CVE-2026-97688","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"urls":["https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97688","description":"urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4340","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4340","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"risk":0.169435,"urls":["https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/724120","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-61730","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"urls":["https://go.dev/cl/724120","https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4340"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61730","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4864","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4864","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"risk":0.16644,"urls":["https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763761","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root.\n\nThe Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."},"relatedVulnerabilities":[{"id":"CVE-2026-32282","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"urls":["https://go.dev/cl/763761","https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4864"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32282","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4175","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4175","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"risk":0.1633,"urls":["https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/723900","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."},"relatedVulnerabilities":[{"id":"CVE-2025-61727","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"urls":["https://go.dev/cl/723900","https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4175"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61727","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."}]},{"artifact":{"id":"c2c0e7362117fe90","cpes":["cpe:2.3:a:pip_developers_\\<distutils_sig_project:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:pip:25.3:*:*:*:*:*:*:*"],"name":"pip","purl":"pkg:pypi/pip@25.3","type":"python","version":"25.3","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"26.2.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qwm4-qh6w-59xr","versionConstraint":"<26.2.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pip","version":"25.3"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-qwm4-qh6w-59xr","fix":{"state":"fixed","versions":["26.2.0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"26.2.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-08","epss":0.00292,"percentile":0.19984}],"risk":0.15476,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-13346","https://github.com/pypa/pip/pull/14110","https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX","http://www.openwall.com/lists/oss-security/2026/07/29/7","https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679","https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-3721.yaml"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qwm4-qh6w-59xr","description":"pip would incorrectly handle doubly-encoded package URLs from indexes"},"relatedVulnerabilities":[{"id":"CVE-2026-13346","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-08","epss":0.00292,"percentile":0.19984}],"urls":["https://github.com/pypa/pip/pull/14110","https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/","http://www.openwall.com/lists/oss-security/2026/07/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13346","description":"pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time."}]},{"artifact":{"id":"c2c0e7362117fe90","cpes":["cpe:2.3:a:pip_developers_\\<distutils_sig_project:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:pip:25.3:*:*:*:*:*:*:*"],"name":"pip","purl":"pkg:pypi/pip@25.3","type":"python","version":"25.3","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"26.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6vgw-5pg2-w6jp","versionConstraint":"<26.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pip","version":"25.3"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-6vgw-5pg2-w6jp","fix":{"state":"fixed","versions":["26.0"],"available":[{"date":"2026-02-03","kind":"first-observed","version":"26.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1703","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1703","date":"2026-10-08","epss":0.00443,"percentile":0.36495}],"risk":0.11075,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-1703","https://github.com/pypa/pip/pull/13777","https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735","https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ"],"severity":"Low","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6vgw-5pg2-w6jp","description":"pip Path Traversal vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2026-1703","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1703","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1703","date":"2026-10-08","epss":0.00443,"percentile":0.36495}],"urls":["https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735","https://github.com/pypa/pip/pull/13777","https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1703","description":"When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations."}]},{"artifact":{"id":"5947b7735846326a","cpes":["cpe:2.3:a:oracleamerica:gawk:5.1.0-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:gawk:gawk:5.1.0-6.el9:*:*:*:*:*:*:*"],"name":"gawk","purl":"pkg:rpm/ol/gawk@5.1.0-6.el9?arch=x86_64&distro=ol-9.8&upstream=gawk-5.1.0-6.el9.src.rpm","type":"rpm","version":"5.1.0-6.el9","language":"","licenses":["GPLv3+ and GPLv2+ and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:5.1.0-6.el9_8.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-73512","versionConstraint":"< 0:5.1.0-6.el9_8.1 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"gawk","version":"0:5.1.0-6.el9"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-73512","fix":{"state":"fixed","versions":["0:5.1.0-6.el9_8.1"],"available":[{"date":"2026-09-30","kind":"advisory","version":"0:5.1.0-6.el9_8.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-40467","cwe":"CWE-416","type":"Secondary","source":"cvd@cert.pl"},{"cve":"CVE-2026-40468","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"},{"cve":"CVE-2026-40553","cwe":"CWE-121","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-40467","date":"2026-10-08","epss":0.00213,"percentile":0.1069},{"cve":"CVE-2026-40468","date":"2026-10-08","epss":0.00201,"percentile":0.09111},{"cve":"CVE-2026-40553","date":"2026-10-08","epss":0.00291,"percentile":0.19814}],"risk":0.1065,"urls":["https://linux.oracle.com/cve/CVE-2026-40467.html","https://linux.oracle.com/cve/CVE-2026-40468.html","https://linux.oracle.com/cve/CVE-2026-40553.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-73512.html","description":"[5.1.0-6.1]\n- Fix use after free in io.c\n- Fix buffer overflow in extensions/readdir.c\n- Fix integer overflow in buildin.c\nResolves: CVE-2026-40467\nResolves: CVE-2026-40468\nResolves: CVE-2026-40553"},"relatedVulnerabilities":[{"id":"CVE-2026-40467","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40467","cwe":"CWE-416","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-40467","date":"2026-10-08","epss":0.00213,"percentile":0.1069}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-40467","https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40467","description":"Use After Free vulnerability has been found in \"io.c\" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below."},{"id":"CVE-2026-40468","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40468","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-40468","date":"2026-10-08","epss":0.00201,"percentile":0.09111}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-40467","https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40468","description":"Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below."},{"id":"CVE-2026-40553","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40553","cwe":"CWE-121","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-40553","date":"2026-10-08","epss":0.00291,"percentile":0.19814}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-40467","https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40553","description":"Buffer overflow vulnerability has been found in \"extension/readdir.c\" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below."}]},{"artifact":{"id":"52027b597325fd67","cpes":["cpe:2.3:a:oracleamerica:libgcrypt:1.10.0-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libgcrypt:libgcrypt:1.10.0-13.el9_8:*:*:*:*:*:*:*"],"name":"libgcrypt","purl":"pkg:rpm/ol/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=ol-9.8&upstream=libgcrypt-1.10.0-13.el9_8.src.rpm","type":"rpm","version":"1.10.0-13.el9_8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10:1.10.0-13.el9_8_fips"},"type":"exact-direct-match","found":{"vulnerabilityID":"ELSA-2026-500145","versionConstraint":"< 10:1.10.0-13.el9_8_fips (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"oraclelinux","version":"9.8"},"package":{"name":"libgcrypt","version":"0:1.10.0-13.el9_8"},"namespace":"oracle:distro:oraclelinux:9"}}],"vulnerability":{"id":"ELSA-2026-500145","fix":{"state":"fixed","versions":["10:1.10.0-13.el9_8_fips"],"available":[{"date":"2026-08-07","kind":"advisory","version":"10:1.10.0-13.el9_8_fips"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-41989","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41989","date":"2026-10-08","epss":0.00192,"percentile":0.08104}],"risk":0.096,"urls":["https://linux.oracle.com/cve/CVE-2026-41989.html"],"severity":"Medium","namespace":"oracle:distro:oraclelinux:9","advisories":[],"dataSource":"https://linux.oracle.com/errata/ELSA-2026-500145.html","description":"[1.10.0-13_fips]\n- Add FIPS package change: add fips suffix to Release and\n  set Epoch to 10 [Orabug: 35961378]\n- Update FIPS module name for Oracle Linux [Orabug: 35961378]\n\n[1.10.0-13]\n- Bump version to fix wrong build target.\n\n[1.10.0.12]\n- Fix CVE-2026-41989: Denial of Service and buffer overflow via crafted ECDH ciphertext"},"relatedVulnerabilities":[{"id":"CVE-2026-41989","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.2,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41989","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41989","date":"2026-10-08","epss":0.00192,"percentile":0.08104}],"urls":["https://dev.gnupg.org/T8211","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html","https://www.openwall.com/lists/oss-security/2026/04/21/1","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41989","description":"Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4869","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4869","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"risk":0.09555000000000001,"urls":["https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763766","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."},"relatedVulnerabilities":[{"id":"CVE-2026-32288","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"urls":["https://go.dev/cl/763766","https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4869"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32288","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."}]},{"artifact":{"id":"c2c0e7362117fe90","cpes":["cpe:2.3:a:pip_developers_\\<distutils_sig_project:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:pip:25.3:*:*:*:*:*:*:*"],"name":"pip","purl":"pkg:pypi/pip@25.3","type":"python","version":"25.3","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"26.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jp4c-xjxw-mgf9","versionConstraint":"<26.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pip","version":"25.3"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-jp4c-xjxw-mgf9","fix":{"state":"fixed","versions":["26.1"],"available":[{"date":"2026-05-06","kind":"first-observed","version":"26.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6357","cwe":"CWE-829","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6357","date":"2026-10-08","epss":0.00171,"percentile":0.0587}],"risk":0.08806499999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-6357","https://github.com/pypa/pip/pull/13923","https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes","http://www.openwall.com/lists/oss-security/2026/04/27/7","https://github.com/pypa/pip/commit/b369bfc96cc524e00c267e1693290e6599c36bad"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jp4c-xjxw-mgf9","description":"pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere"},"relatedVulnerabilities":[{"id":"CVE-2026-6357","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6357","cwe":"CWE-829","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6357","date":"2026-10-08","epss":0.00171,"percentile":0.0587}],"urls":["https://github.com/pypa/pip/pull/13923","https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes","http://www.openwall.com/lists/oss-security/2026/04/27/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6357","description":"pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation."}]},{"artifact":{"id":"c2c0e7362117fe90","cpes":["cpe:2.3:a:pip_developers_\\<distutils_sig_project:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python-pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:python_pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:python:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pypa:pip:25.3:*:*:*:*:*:*:*","cpe:2.3:a:pip:pip:25.3:*:*:*:*:*:*:*"],"name":"pip","purl":"pkg:pypi/pip@25.3","type":"python","version":"25.3","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/pip-25.3.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"26.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-58qw-9mgm-455v","versionConstraint":"<=26.0.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pip","version":"25.3"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-58qw-9mgm-455v","fix":{"state":"fixed","versions":["26.1"],"available":[{"date":"2026-05-21","kind":"first-observed","version":"26.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3219","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3219","date":"2026-10-08","epss":0.0018,"percentile":0.06987}],"risk":0.08639999999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-3219","https://github.com/pypa/pip/pull/13870","https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ","http://www.openwall.com/lists/oss-security/2026/04/20/8","https://github.com/pypa/pip/issues/13867"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-58qw-9mgm-455v","description":"pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files"},"relatedVulnerabilities":[{"id":"CVE-2026-3219","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3219","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3219","date":"2026-10-08","epss":0.0018,"percentile":0.06987}],"urls":["https://github.com/pypa/pip/pull/13870","https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ/","http://www.openwall.com/lists/oss-security/2026/04/20/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3219","description":"pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both."}]},{"artifact":{"id":"1f7c407a4dbe7f15","cpes":["cpe:2.3:a:golang:x\\/sys:v0.1.0:*:*:*:*:*:*:*"],"name":"golang.org/x/sys","purl":"pkg:golang/golang.org/x/sys@v0.1.0","type":"go-module","version":"v0.1.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:kunALQeHf1/185U1i0GOB/fy1IPRDDpuoOOqRReG57U=","mainModule":"github.com/tianon/gosu","architecture":"amd64","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.44.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5024","versionConstraint":"<0.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/sys","version":"v0.1.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5024","fix":{"state":"fixed","versions":["0.44.0"],"available":[{"date":"2026-04-23","kind":"release","version":"0.44.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"risk":0.04976999999999999,"urls":["https://go.dev/cl/770080","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78916","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."},"relatedVulnerabilities":[{"id":"CVE-2026-39824","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"urls":["https://go.dev/cl/770080","https://go.dev/issue/78916","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg","https://pkg.go.dev/vuln/GO-2026-5024"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39824","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4602","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4602","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"risk":0.03245,"urls":["https://go.dev/issue/77827","https://go.dev/cl/749480"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened.\n\nThe impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."},"relatedVulnerabilities":[{"id":"CVE-2026-27139","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"urls":["https://go.dev/cl/749480","https://go.dev/issue/77827","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4602"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27139","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."}]},{"artifact":{"id":"3f1bb178488b64cc","cpes":["cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@46.0.7","type":"python","version":"46.0.7","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/METADATA","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/RECORD","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/direct_url.json","layerID":"sha256:1a0f5d7618e6aa154637989df6f0cb9a045538d32f8d91040f3bdbdf8f3375ac","accessPath":"/usr/lib/mysqlsh/lib/python3.13/site-packages/cryptography-46.0.7.dist-info/direct_url.json","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"48.0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-537c-gmf6-5ccf","versionConstraint":">=0.5.0,<48.0.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"46.0.7"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-537c-gmf6-5ccf","fix":{"state":"fixed","versions":["48.0.1"],"available":[{"date":"2026-06-16","kind":"first-observed","version":"48.0.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-537c-gmf6-5ccf","description":"Vulnerable OpenSSL included in cryptography wheels"},"relatedVulnerabilities":[]},{"artifact":{"id":"d2a8da7f933cc6b6","cpes":["cpe:2.3:a:moby:sys\\/user:v0.1.0:*:*:*:*:*:*:*"],"name":"github.com/moby/sys/user","purl":"pkg:golang/github.com/moby/sys/user@v0.1.0","type":"go-module","version":"v0.1.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:WmZ93f5Ux6het5iituh9x2zAG7NFY9Aqi49jjE1PaQg=","mainModule":"github.com/tianon/gosu","architecture":"amd64","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.4.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mjcv-p78q-w5fw","versionConstraint":"<=0.4.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/moby/sys/user","version":"v0.1.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-mjcv-p78q-w5fw","fix":{"state":"fixed","versions":["0.4.1"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"0.4.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61801","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"risk":0,"urls":["https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw","https://github.com/moby/sys/pull/221","https://github.com/moby/sys/commit/85a71bbe1faa36c552a960e6a5f3d0cfb632fbbe"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mjcv-p78q-w5fw","description":"github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group database files"},"relatedVulnerabilities":[{"id":"CVE-2026-61801","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61801","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"urls":["https://github.com/moby/sys/commit/85a71bbe1faa36c552a960e6a5f3d0cfb632fbbe","https://github.com/moby/sys/pull/221","https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61801","description":"The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries when parsing `/etc/passwd`- or `/etc/group`-style files, allowing an attacker who can supply a specially crafted file to cause excessive memory consumption and potentially terminate the affected process due to an out-of-memory condition. This issue is patched in version 0.4.1. As a workaround, avoid parsing attacker-controlled user or group database files, or validate and limit untrusted input before parsing it."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:7d64d1cf94ebffe67ccd3dd6aff1a80be34eeebef4341da6bb9d06d879bd8776","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:04:06.543Z","grype_db_version":"2026-10-09T06:32:32.000Z"}