{"grype_matches":[{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"7defdd634b5a5ad3","cpes":["cpe:2.3:a:netty-codec-dns:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-dns:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_dns:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_dns:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-dns","purl":"pkg:maven/io.netty/netty-codec-dns@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":[],"metadata":{"pomGroupID":"io.netty","virtualPath":"/app/metabase.jar:io.netty:netty-codec-dns","manifestName":"","pomArtifactID":"netty-codec-dns","archiveDigests":null},"locations":[{"path":"/app/metabase.jar","layerID":"sha256:ff3745ed11cd0c847509009a61c125e6f750f12336a7a400c2e187d696210461","accessPath":"/app/metabase.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mfg7-5gfp-c4w3","versionConstraint":"<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-dns","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mfg7-5gfp-c4w3","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-25","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73508","cwe":"CWE-772","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73508","date":"2026-10-08","epss":0.00382,"percentile":0.30064}],"risk":0.19673,"urls":["https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3","https://github.com/netty/netty/pull/17063","https://github.com/netty/netty/pull/17065","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mfg7-5gfp-c4w3","description":"Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names"},"relatedVulnerabilities":[{"id":"CVE-2026-73508","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73508","cwe":"CWE-772","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73508","date":"2026-10-08","epss":0.00382,"percentile":0.30064}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73508","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"d2b14d010486d3e1","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/app/metabase.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/app/metabase.jar","layerID":"sha256:ff3745ed11cd0c847509009a61c125e6f750f12336a7a400c2e187d696210461","accessPath":"/app/metabase.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v53-57pg-c464","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v53-57pg-c464","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","https://nvd.nist.gov/vuln/detail/CVE-2026-106452","https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v53-57pg-c464","description":"yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header"},"relatedVulnerabilities":[{"id":"CVE-2026-106452","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"d2b14d010486d3e1","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/app/metabase.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/app/metabase.jar","layerID":"sha256:ff3745ed11cd0c847509009a61c125e6f750f12336a7a400c2e187d696210461","accessPath":"/app/metabase.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cx8-rjf8-pr8g","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cx8-rjf8-pr8g","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","https://nvd.nist.gov/vuln/detail/CVE-2026-106453","https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cx8-rjf8-pr8g","description":"yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError"},"relatedVulnerabilities":[{"id":"CVE-2026-106453","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"d2b14d010486d3e1","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/app/metabase.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/app/metabase.jar","layerID":"sha256:ff3745ed11cd0c847509009a61c125e6f750f12336a7a400c2e187d696210461","accessPath":"/app/metabase.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm45-99xc-r7wv","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gm45-99xc-r7wv","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","https://nvd.nist.gov/vuln/detail/CVE-2026-106450","https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm45-99xc-r7wv","description":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-106450","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"fef07e9c95ea2bda","cpes":["cpe:2.3:a:busybox:busybox:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox","purl":"pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/busybox"},{"path":"/etc"},{"path":"/etc/securetty"},{"path":"/etc/busybox-paths.d"},{"path":"/etc/busybox-paths.d/busybox"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/acpid"},{"path":"/etc/network"},{"path":"/etc/network/if-down.d"},{"path":"/etc/network/if-post-down.d"},{"path":"/etc/network/if-post-up.d"},{"path":"/etc/network/if-pre-down.d"},{"path":"/etc/network/if-pre-up.d"},{"path":"/etc/network/if-up.d"},{"path":"/etc/network/if-up.d/dad"},{"path":"/etc/udhcpc"},{"path":"/etc/udhcpc/udhcpc.conf"},{"path":"/sbin"},{"path":"/usr"},{"path":"/usr/sbin"},{"path":"/usr/share"},{"path":"/usr/share/udhcpc"},{"path":"/usr/share/udhcpc/default.script"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"915155597fcdee9a","cpes":["cpe:2.3:a:busybox-binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox-binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox-binsh","purl":"pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/sh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"8a9ef44e1018f213","cpes":["cpe:2.3:a:ssl-client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl-client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl_client:1.37.0-r31:*:*:*:*:*:*:*"],"name":"ssl_client","purl":"pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssl_client"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"d2b14d010486d3e1","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/app/metabase.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/app/metabase.jar","layerID":"sha256:ff3745ed11cd0c847509009a61c125e6f750f12336a7a400c2e187d696210461","accessPath":"/app/metabase.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-343h-94h5-c4wr","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-343h-94h5-c4wr","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"risk":0.11356499999999997,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","https://nvd.nist.gov/vuln/detail/CVE-2026-106449","https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-343h-94h5-c4wr","description":"yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError"},"relatedVulnerabilities":[{"id":"CVE-2026-106449","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"urls":["https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:04aa37f3670235b1cb7a8d9160aca34546c2cb78ca2931de3225d9781fc34c77","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"d2b14d010486d3e1","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.1","type":"java-archive","version":"1.11.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/app/metabase.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/app/metabase.jar","layerID":"sha256:ff3745ed11cd0c847509009a61c125e6f750f12336a7a400c2e187d696210461","accessPath":"/app/metabase.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mcr4-qmvw-px4g","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mcr4-qmvw-px4g","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"risk":0.061419999999999995,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g","https://nvd.nist.gov/vuln/detail/CVE-2026-106451","https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mcr4-qmvw-px4g","description":"yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user"},"relatedVulnerabilities":[{"id":"CVE-2026-106451","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"urls":["https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","description":"yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4."}]}],"grade":"A","score":"90.00","as_of":"2026-10-10T05:20:25.715Z","grype_db_version":"2026-10-09T06:32:32.000Z"}